Authentication and Authorization on the Web

Authentication and Authorization on the Web
Author :
Publisher :
Total Pages : 246
Release :
ISBN-10 : 0956737056
ISBN-13 : 9780956737052
Rating : 4/5 (052 Downloads)

Book Synopsis Authentication and Authorization on the Web by : Nigel Chapman

Download or read book Authentication and Authorization on the Web written by Nigel Chapman and published by . This book was released on 2012-10 with total page 246 pages. Available in PDF, EPUB and Kindle. Book excerpt: A short book in the "Web Security Topics" series for Web developers, by the well-known authors Nigel and Jenny Chapman. Web applications manipulate resources in response to requests from users. It is often necessary to determine whether a requested operation should be allowed for the user who sent the request. This process of authorization - that is, deciding whether an application should be allowed to carry.out the operation which a request from a particular user or program calls for - depends on, but is separate from, the process of authentication. Authentication means determining the identity of the user or program sending the request. This is usually done by maintaining user accounts, protected by passwords, and by requiring users to log in. Written for professional and student Web developers, this book provides a clear and practical description of authentication and authorization for Web sites. Secure methods of storing users' account details are described, with special emphasis on the secure storage of passwords. The authors explain different methods of authentication, and techniques for applying authorization to requests from authenticated users. A simple application, written in JavaScript and built on the Express framework, is developed throughout the book to demonstrate the principles. The source code is provided via the companion site websecuritytopics.info. Topics covered include hashing and salting passwords for secure storage, using CAPTCHAs to prevent the creation of bogus accounts, resetting passwords, session-based authentication and attacks against sessions, HTTP authentication, OpenId, authorization based on user accounts, role-based authorization, and OAuth. Notes on relevant topics in cryptography are also included. Clear key points provide useful summaries at the end of each section, and technical terms are defined in a 16-page glossary.


Authentication and Authorization on the Web Related Books

Authentication and Authorization on the Web
Language: en
Pages: 246
Authors: Nigel Chapman
Categories: Computers
Type: BOOK - Published: 2012-10 - Publisher:

DOWNLOAD EBOOK

A short book in the "Web Security Topics" series for Web developers, by the well-known authors Nigel and Jenny Chapman. Web applications manipulate resources in
Networked Digital Technologies
Language: en
Pages: 457
Authors: Simon Fong
Categories: Computers
Type: BOOK - Published: 2011-06-27 - Publisher: Springer

DOWNLOAD EBOOK

This book constitutes the proceedings of the Third International Conference on Networked Digital Technologies, held in Macau, China, in July 2011. The 41 revise
Hands-On Full-Stack Web Development with ASP.NET Core
Language: en
Pages: 478
Authors: Tamir Dresher
Categories: Computers
Type: BOOK - Published: 2018-10-31 - Publisher: Packt Publishing Ltd

DOWNLOAD EBOOK

Become a full-stack developer by learning popular Microsoft technologies and platforms such as .NET Core, ASP.NET Core, Entity Framework, and Azure Key Features
Essential PHP Security
Language: en
Pages: 128
Authors: Chris Shiflett
Categories: Computers
Type: BOOK - Published: 2005-10-13 - Publisher: "O'Reilly Media, Inc."

DOWNLOAD EBOOK

Being highly flexible in building dynamic, database-driven web applications makes the PHP programming language one of the most popular web development tools in
Service-Oriented and Cloud Computing
Language: en
Pages: 292
Authors: Flavio De Paoli
Categories: Computers
Type: BOOK - Published: 2012-08-23 - Publisher: Springer

DOWNLOAD EBOOK

This book constitutes the refereed proceedings of the First European Conference on Service-Oriented and Cloud Computing, ESOCC, held in Bertinoro, Italy, in Sep