# Authentication और Authorisation — API Design और Versioning

Source: https://www.geekswithgeeks.com/hi/api-design/sec-auth

> API keys, OAuth 2.0 या JWTs को उचित रूप से चुनें और least-privilege scopes लागू करें।

## आप कौन हैं, और आप क्या कर सकते हैं?

**Authentication** पहचान साबित करता है; **authorisation** तय करता है कि वह पहचान क्या कर सकती है। **API keys** server-से-server access के लिए सरल हैं और application की पहचान बताती हैं, पर वे लंबी अवधि के secrets हैं: उन्हें header में भेजें (URL में कभी नहीं), rotation और रद्द करना संभव रखें, और उनका दायरा सीमित करें। जब users किसी तृतीय-पक्ष ऐप को अपने डेटा तक सीमित access देते हैं तब **OAuth 2.0** (login के लिए OpenID Connect के साथ) मानक है: **scopes** (`orders:read`) वाले अल्पकालिक **access tokens** और refresh tokens; ऐप्स के लिए PKCE के साथ authorisation-code flow उपयोग करें। **JWTs** हस्ताक्षरित tokens हैं जो claims रखते हैं; हर call पर signature, issuer, audience और expiry जाँचें। हमेशा **HTTPS** उपयोग करें, server पर **हर अनुरोध** पर authorisation जाँचें, और उचित रूप से `401` या `403` लौटाएँ।

## जाँचें, सीमित करें, न्यूनतम रखें

हर caller authenticate करें, हर object access जाँचें और सिर्फ़ ज़रूरी उजागर करें।

![तीन कर्तव्य: authenticate, authorise, न्यूनतम।](assets/figures/api-design/section-4-map.svg) — चित्र 4.1 — Authenticate, authorise और न्यूनतम।

## OpenAPI security scheme में scopes (उदाहरण)

Scopes token को सिर्फ़ उन ऑपरेशनों तक सीमित करने देते हैं जो client को सचमुच चाहिए।

```yaml
components:
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://auth.example.com/authorize
          tokenUrl: https://auth.example.com/token
          scopes:
            orders:read: Read orders
            orders:write: Create and change orders
security:
  - oauth2: [orders:read]
```

## URLs में secrets कभी न रखें

URLs logs, browser history और referrer headers में पहुँच जाते हैं। Tokens `Authorization` header में भेजें, query strings में नहीं।

**Quiz:** Access token कहाँ भेजना चाहिए?

- [ ] URL query string में
- [x] HTTPS पर Authorization header में
- [ ] पन्ने के शीर्षक में
- [ ] सार्वजनिक repository में

*Answer:* HTTPS पर Authorization header में. TLS पर headers credentials को logs और history में लीक होने से बचाते हैं।
