REST Authorization: Username/Password in Authorization Header vs JSON body

后端 未结 1 1445
南方客
南方客 2021-01-14 04:33

I\'m using a token style authentication process. After the client has obtained a token, it is either set in the client\'s cookies (for Web) or the authorization headers of t

1条回答
  •  北海茫月
    2021-01-14 04:51

    There's no added security in sending credentials in the Authorization header vs. a JSON body. The advantage in using the Authorization header is that you leverage on the standardized HTTP semantics, and you don't have to document exactly what clients should do. You can simply point them to the RFCs.

    If you're concerned about being really RESTful, I'd say using the Authorization header instead of rolling your own method is a must.

    0 讨论(0)
提交回复
热议问题