I recently thought about how to properly get my webframework / application-stack. I am slowly moving on to scala and functional programming (from Python using CherryPy). Thus, it was natural to watch on Play, as it is the most widely supported infrastructure (now that even SafeSafe has adopted it). Feel free to correct me if I missed something.
Thus, the game really embraces the idea of ββstand-alone web applications, and it's hard for me to wrap it around it in terms of authentication and authorization. Now, after some online digging (the final form-based authentication guide ), I came to the conclusion that authentication and authorization should be done every time I call my backend (JSON-RPC or something else), getting away from the old idea of ββa cookie session .
Now, what is the best approach to achieve this with today's technology?
What about:
I was thinking of the βsimpleβ DigestAuth as it is proven and widespread, but then it has the same feeling as the old and rusty base auth.
Thanks!
Alessandroemmm
source share