|
|
|
|
|
by arethuza
5278 days ago
|
|
What's wrong with an approach of: - For client access to a server, use basic auth over HTTPS - For client/server to server access, use OAuth Note - I'm genuinely interested what people think as I'm just finishing off a personal project using a RESTful interface and this is the approach I have used so far. [Edited based on comment - and I should point out that I haven't implemented OAuth yet but I should really check out how it would work]. |
|
On the other hand, it makes it more difficult for developers to access your API; you can't just send requests over Curl, for instance.