We use the RESTful api for a rich client. 
 
There is a similar risk level having the TGT stored in rich client
memory as there is in having the TGT stored in an Internet Explorer
session cookie.
 
So I think rich clients are a second valid use-case for the RESTful api.

________________________________

From: Robert Winch [mailto:[email protected]] 
Sent: Tuesday, 28 July 2009 6:14 a.m.
To: [email protected]
Subject: Re: [cas-dev] CAS RESTful API - Is including the TGT in the URI
safe?


We are wanting to use it for rich client (desktop) applications
authenticating to web services (both soap and REST). The reason for this
is we want a consistent method for authenticating to the services for
both web applications and rich client applications. We planned on
allowing the ST or PT to be resused, as is done in the Spring Security's
stateless mode, in order to prevent the CAS server from being
overwhelmed. Any suggestions on this would be greatly appreciated.

Thanks again,
Rob

 

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-dev

Reply via email to