पाठ 13 / 27
Authentication और Authorisation
API keys, OAuth 2.0 या JWTs को उचित रूप से चुनें और least-privilege scopes लागू करें।
आप कौन हैं, और आप क्या कर सकते हैं?
Authentication पहचान साबित करता है; authorisation तय करता है कि वह पहचान क्या कर सकती है। API keys server-से-server access के लिए सरल हैं और application की पहचान बताती हैं, पर वे लंबी अवधि के secrets हैं: उन्हें header में भेजें (URL में कभी नहीं), rotation और रद्द करना संभव रखें, और उनका दायरा सीमित करें। जब users किसी तृतीय-पक्ष ऐप को अपने डेटा तक सीमित access देते हैं तब OAuth 2.0 (login के लिए OpenID Connect के साथ) मानक है: scopes (orders:read) वाले अल्पकालिक access tokens और refresh tokens; ऐप्स के लिए PKCE के साथ authorisation-code flow उपयोग करें। JWTs हस्ताक्षरित tokens हैं जो claims रखते हैं; हर call पर signature, issuer, audience और expiry जाँचें। हमेशा HTTPS उपयोग करें, server पर हर अनुरोध पर authorisation जाँचें, और उचित रूप से 401 या 403 लौटाएँ।
जाँचें, सीमित करें, न्यूनतम रखें
हर caller authenticate करें, हर object access जाँचें और सिर्फ़ ज़रूरी उजागर करें।
OpenAPI security scheme में scopes (उदाहरण)
Scopes token को सिर्फ़ उन ऑपरेशनों तक सीमित करने देते हैं जो client को सचमुच चाहिए।
components:
securitySchemes:
oauth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.example.com/authorize
tokenUrl: https://auth.example.com/token
scopes:
orders:read: Read orders
orders:write: Create and change orders
security:
- oauth2: [orders:read]URLs में secrets कभी न रखें
URLs logs, browser history और referrer headers में पहुँच जाते हैं। Tokens Authorization header में भेजें, query strings में नहीं।
त्वरित जाँच: Access token कहाँ भेजना चाहिए?
- URL query string में
- HTTPS पर Authorization header में
- पन्ने के शीर्षक में
- सार्वजनिक repository में
Answer
HTTPS पर Authorization header में — TLS पर headers credentials को logs और history में लीक होने से बचाते हैं।