KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am building a REST API in PHP to work with a JavaScript based app. All requests are handled as JSON and some requests require authentication. An example request would be: $.ajax({ type: 'GET', url: 'http://domain.com/api/posts/recent.json', headers: { Authorization: 'X-TRUEREST ' + $.param({ username: 'johndoe', password: '********' }) }, success: function(response){ // Handle response here (includes auth errors too) }, error: function(a,b,c) { } }); I have based the use of HTTP Authentication headers on the code in this plugin: https://github.com/kvz/cakephp-rest-plugin/blob/master/Controller/Component/RestComponent.php#L532 As you can see they take passed parameters with the header and then they are used to log a user into the system if they are not already. From what I can tell they expect the auth credentials to be passed WITH the request for data. An example of this is (note not using CakePHP in my example app): if ( $loggedIn ) { // logged in is true of false based on session existing // Then return the JSON as normal } else { // Grab HEADERS INFO $headers = $_SERVER['HTTP_AUTHORIZATION']; $parts = explode(' ', $_SERVER['HTTP_AUTHORIZATION']); // Then use the parts to find a user in the DB... and populate $user if($user){ $this->Auth->login($user); // login the user with our authentication code // Then return JSON as normal } else { print json_encode(array('auth'=>false)) } } A few questions that I have though: Question 1: Why use the HTTP Authentication and headers? As as far as I can tell, they are not offering me anything unless I am using t
Tags (comma-separated)
Save Edits
Cancel