InfoQ

InfoQ

Topic/Tag specific view

Authorization Content on InfoQ


Latest featured content about Authorization

Who are You? Who am I? Who is Anybody?

Topics
OAuth,
OpenID,
Authorization,
GOTO 2011,
HTTP,
GOTO Conference,
Identity Management,
W3C,
REST,
Architecture,
Security,
Conferences,
Enterprise,
Enterprise Architecture,
Internet,
Specifications

Paul Downey talks on the current status of identity management on the web covering cross-site challenges, REST, HTTPS, Open ID, all in the context of enterprise architecture.

News about Authorization

Twitter Experiences Site Instability Following Google, Microsoft Outages

Topics
OAuth,
Twitter API,
Authorization,
Public APIs,
API,
Operations,
Identity Management,
Programming,
Infrastructure,
Cloud Computing,
Security

Twitter is the latest to experience downtime when yesterday the company issued a status update indicating instability within the site. This was the second such report from Twitter this week and follows on the heels of outages experienced this week by Google’s Blogger service and Microsoft’s Business Productivity Online Suite (BPOS).

Google Debuts OAuth 2.0 Support for Google APIs

Topics
OAuth,
Authorization,
Data Access,
Operations,
Google,
Identity Management,
Database,
Architecture,
Infrastructure,
Companies,
Security

Today Google announced experimental support for OAuth 2.0 with bearer tokens. In addition, as a side announcement they've launched a new consent page for OAuth 2.0 designed with cleanliness and simplicity in mind.

A Proposal for an HTTP Digital Signature Protocol and API

Topics
OAuth,
HTTP,
Authorization,
REST,
W3C,
Identity Management,
Architecture,
Enterprise Architecture,
Security,
Specifications,
Digital Signature

Bill Burke, JBoss's Chief Architect and REST Easy Project Lead, published last week a proposal for a Digital Signature Protocol over HTTP. "DSig" is rapidly gaining popularity, more than 10 years after it was designed, due to the emergence of composite applications and the need to establish trusted relationships between their clients and services.

Is OAuth 2.0 Bad for the Web?

Topics
OAuth,
Authorization,
Identity Management,
Architecture,
Security

Eran Hammer-Lahav, one of the editors of the OAuth 2.0 specification, published a diatribe on the latest standard draft. For him, the current proposal mortgages the future of the Web. He sees the current specification focusing too much on simplicity for the application developer while severely limiting the ability to create discoverable and interoperable services.

Presentations about Authorization

Spring Social: For the New Web of APIs

Topics
SpringOne 2GX 2011,
SpringOne,
Spring,
OAuth,
Conferences,
Authorization,
Dependency Injection,
SpringSource,
Java,
VMWare,
Identity Management,
Languages,
Design Pattern,
Spring Social,
Social Networking,
Object Oriented Design,
Patterns,
Security,
Companies,
Design,
Programming

Craig Walls discusses the need for adding social features to applications, how to secure such applications and how Spring Social can help.

The Rise of OAuth

Topics
SpringOne 2GX 2011,
SpringOne,
Spring,
OAuth,
Conferences,
Dependency Injection,
Java,
Authorization,
SpringSource,
VMWare,
Languages,
Design Pattern,
Identity Management,
Companies,
Object Oriented Design,
Spring Security,
Design,
Security,
Programming,
Patterns

Craig Walls talks about securing the modern web and how OAuth can help with that, showing how to secure and consume resources with OAuth.

Getting Started With Spring Security 3.1

Topics
SpringOne 2GX 2011,
SpringOne,
Spring,
Conferences,
Authentication,
Java,
SpringSource,
Dependency Injection,
Authorization,
Languages,
Identity Management,
Design Pattern,
VMWare,
Security,
Programming,
Object Oriented Design,
Patterns,
Design,
Companies,
Spring Security

Rob Winch demoes some of the new features in Spring Security 3.1: multiple http elements, stateless authentication mode for RESTful services, Debug Filter, CAS support for proxy tickets, JAAS, etc.

Interviews about Authorization

REST and the Web as a Platform, with Subbu Allamaraju

Topics
OAuth,
QCon San Francisco 2010,
Authorization,
REST,
SOA,
QCon,
Patterns and Practices,
Identity Management,
Architecture,
Enterprise Architecture,
Conferences,
Patterns,
Security

In this interview, Subbu Allamaraju talks about real life issues of RESTful architectures. He also describes a pragmatic approach of adopting the Web as an integration platform and shares his opinion on OAuth.

Laforge and Rocher Discuss the future of Groovy, Grails and Java

Topics
JVM,
Grails,
Virtual Machines,
MongoDB,
Java Web Frameworks,
Groovy,
OAuth,
Runtimes,
Java,
Flex,
Domain Specific Languages,
Dynamic Languages,
Distributed Document Oriented Database,
OpenID,
JVM Languages,
Authorization,
Flash,
NoSQL,
Languages,
Identity Management,
Adobe,
Database,
Security,
Programming,
GemFire,
Companies,
Rich Internet Apps,
MapReduce,
Spring Roo

In this interview, Graeme Rocher and Guillaume Laforge of SpringSource talk about the present and future of the Grails framework and the Groovy language. Rocher talks about Grails 1.4 and some of its enhancements such as improvements to GORM. And Laforge discusses Groovy 1.8, which features new DSL authoring capabilities, among other things. They look at how Java’s future impacts their projects.

Inside SpringSource with Rod Johnson

Topics
Spring Integration,
AMQP,
Neo4j,
SpringOne,
GWT,
Java EE,
Spring,
Java Annotations,
Messaging,
Conferences,
OAuth,
Neo,
Graph Database,
Dynamic Languages,
Dependency Injection,
Java Web Frameworks,
SpringSource,
Authorization,
AJAX,
Java,
Annotations,
Web Services,
Continuous Integration,
Google AppEngine,
Design Pattern,
SOA,
Agile Techniques,
Rich Internet Apps,
Enterprise Architecture,
Languages,
VMWare,
NoSQL,
PaaS,
Google,
Identity Management,
Cloud Computing,
Language,
Apache Harmony,
Patterns,
Object Oriented Design,
Spring Insight,
Agile,
Design,
Eclipse,
Companies,
Programming,
GemFire,
GemStone,
AOP,
tc Server,
Architecture,
AspectJ,
Spring Roo,
Database,
Redis,
Aspect Oriented Programming,
Security,
dmServer,
Code Generation

In this interview conducted at the SpringOne 2GX conference, Rod Johnson talks about the new advancements SpringSource is bringing to the enterprise Java space, including new cloud options. Johnson discusses open-source Java in general, including the flap over the direction of OpenJDK and Apache Harmony. And he delves into the new Code2Cloud effort from SpringSource and Tasktop, and much more.