SOAP: Handling Logins

From: ensnare (ensnare_at_gmail.com)
Date: 06/30/04

  • Next message: Geoff Berrow: "Re: Friend Connection Query"
    Date: 30 Jun 2004 00:16:18 -0700
    
    

    I currently have a site with a large database of member information
    (user,password, first name, last name, yada, yada). I'm looking to
    create an API off which other sites can interface with my user
    database -- obtain limited information, user interests, etc...

    So let's assume a website has its own login form which authenticates
    users against my database (all over SOAP). It sends a username and
    password to my server; if the user / pass is valid, soap returns true
    and the user is allowed to login.

    The problem is, this setup would allow the website to cache and store
    the usernames and passwords thus duplicating my unique database and
    opening up security vulnerabilities.

    Is there an architecture that can be established to allow external
    sites to build off my system and to allow users to authenticate
    against my database without the possiblity of storing the data?

    Any ideas would be greatly appreciated!


  • Next message: Geoff Berrow: "Re: Friend Connection Query"

    Relevant Pages

    • Re: Last nights Panorama - totally one-sided
      ... ...yada yada yada snip snip snip... ... But surely you can conceive of a universal DNA database that's e.g. only ... that is pervasive across Britain. ...
      (uk.politics.misc)
    • Re: Re: Need help with using HTTP from VBA in Access 2003.
      ... See http://www.QBuilt.com for all your database needs. ... was for a charity to tutor disadvantaged youth, yada, yada, yada. ... I need to interact with a MySQL database via HTTP strings. ... The PHP script executes the query and sends back the results in XML. ...
      (microsoft.public.access.forms)
    • Re: SOAP: Handling Logins
      ... > (user,password, first name, last name, yada, yada). ... > So let's assume a website has its own login form which authenticates ... > users against my database. ... It sends a username and ...
      (comp.lang.php)
    • Re: Pathname to access and usernames in shortcut
      ... >> network drive (for maintenance reasons initially, ... >> using usernames but no passwords. ... change their passwords within the access database (they won't know how ... >> gets the current username from the system and then calls access (via the ...
      (microsoft.public.access.security)
    • Re: Getting NT User Login Names from Access 2000 or 2003
      ... time, i can recreate it in the blank database, per all your other thoughts. ... In the table setup and adding the bound SomeOtherField field to the ... >> form, plus binding the orig MyUserName field, defaulted to fOSUsername, to ... using the username field as ...
      (microsoft.public.access.formscoding)