Igo*_*tis 17 authentication rpc authorization thrift
我正在开发一个使用thrift的系统.我希望检查客户端身份并对ACL进行操作.Thrift是否为那些人提供任何支持?
Phi*_*ham 13
不是直接的.执行此操作的唯一方法是使用在服务器上创建(临时)密钥的身份验证方法,然后更改所有方法,以便第一个参数是此密钥,并且它们还会引发未经过身份验证的错误.例如:
exception NotAuthorisedException {
1: string errorMessage,
}
exception AuthTimeoutException {
1: string errorMessage,
}
service MyAuthService {
string authenticate( 1:string user, 2:string pass )
throws ( 1:NotAuthorisedException e ),
string mymethod( 1:string authstring, 2:string otherargs, ... )
throws ( 1:AuthTimeoutException e, ... ),
}
Run Code Online (Sandbox Code Playgroud)
我们使用这种方法并将我们的密钥保存到一个安全的memcached实例,并使用30分钟的超时时间来保持所有内容"干净".接收AuthTimeoutException到的客户需要重新授权和重试,我们有一些防火墙规则来阻止暴力攻击.
| 归档时间: |
|
| 查看次数: |
6181 次 |
| 最近记录: |