I was dealing with web services and we provided it with a soap credential header. The calling application will need to enter a username and password in the credential header. We are now exploring the use of a WCF-based web service and want to protect it. I wonder what is the best way to protect him?
I thought I could use the username and password in the POST variables (this is what they are called). But is this really a way to provide a calm web service?
source
share