HTTP APIs

261 posts

HTTP APIs banner
HTTP APIs

HTTP APIs

@http_apis

Bits and tweets about HTTP based Application Programming Interfaces. By @pmhsfelix

Присоединился Ağustos 2018
2 Подписки194 Подписчики
HTTP APIs
HTTP APIs@http_apis·
"To address this, this memo defines a path prefix in HTTP(S) URIs for these "well-known locations", "/.well-known/"." In tools.ietf.org/html/rfc5785 (2/2)
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"It is increasingly common for Web-based protocols to require the discovery of policy or other information about a host ("site-wide metadata") before making a request." (1/2)
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"The immutable HTTP response Cache-Control extension allows servers to identify resources that will not be updated during their freshness lifetime. This ensures that a client never needs to revalidate a cached fresh resource (...)" In tools.ietf.org/html/rfc8246
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"The Link header field provides a means for serialising one or more links into HTTP headers." In #section-3" target="_blank" rel="nofollow noopener">tools.ietf.org/html/rfc8288#s
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
Early hints example from tools.ietf.org/html/rfc8297 HTTP/1.1 103 Early Hints Link: </style.css>; rel=preload; as=style Link: </script.js>; rel=preload; as=script HTTP/1.1 200 OK Date: Fri, 26 May 2017 10:02:11 GMT (...)
English
0
2
2
0
HTTP APIs
HTTP APIs@http_apis·
"This memo introduces an informational HTTP status code that can be used to convey hints that help a client make preparations for processing the final response." In tools.ietf.org/html/rfc8297
English
0
1
0
0
HTTP APIs
HTTP APIs@http_apis·
"acr - Authentication Context Class Reference - String specifying an Authentication Context Class Reference value that identifies the Authentication Context Class that the authentication performed satisfied" In #IDToken" target="_blank" rel="nofollow noopener">openid.net/specs/openid-c…
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"azp - Authorized Party - the party to which the ID Token was issued. (...) This Claim is only needed when the ID Token has a single audience value and that audience is different than the authorized party" In #IDToken" target="_blank" rel="nofollow noopener">openid.net/specs/openid-c…
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"The "aud" (audience) claim identifies the recipients that the JWT is intended for. Each principal intended to process the JWT MUST identify itself with a value in the audience claim." In #section-4.1.3" target="_blank" rel="nofollow noopener">tools.ietf.org/html/rfc7519#s
English
0
1
0
0
HTTP APIs
HTTP APIs@http_apis·
"The "sub" (subject) claim identifies the principal that is the subject of the JWT. The claims in a JWT are normally statements about the subject." in #section-4.1.2" target="_blank" rel="nofollow noopener">tools.ietf.org/html/rfc7519#s
English
0
0
0
0
HTTP APIs
HTTP APIs@http_apis·
"The "iss" (issuer) claim identifies the principal that issued the JWT." In #section-4.1.1" target="_blank" rel="nofollow noopener">tools.ietf.org/html/rfc7519#s
English
0
0
0
0
HTTP APIs ретвитнул
HTTP APIs
HTTP APIs@http_apis·
"What makes HTTP significantly different from RPC is that the requests are directed to resources using a generic interface with standard semantics that can be interpreted by intermediaries (..) " In "HTTP is not RPC" by @fielding #sec_6_5_2" target="_blank" rel="nofollow noopener">ics.uci.edu/~fielding/pubs…
English
0
4
2
0
HTTP APIs
HTTP APIs@http_apis·
"The Web is based on numerous standards that together make up the surface of the Web: By knowing and supporting those standards, problems can be solved in well-known ways." By @dret, in dret.net/netdret/docs/w…
English
0
3
3
0
HTTP APIs
HTTP APIs@http_apis·
"If the same issuer can issue JWTs that are intended for use by more than one relying party or application, the JWT MUST contain an "aud" (audience) claim that can be used to determine whether the JWT is being used by an intended party (...)" In #name-use-and-validate-audience" target="_blank" rel="nofollow noopener">rfc-editor.org/rfc/rfc8725.ht…
English
0
1
0
0
HTTP APIs
HTTP APIs@http_apis·
"Sometimes, one kind of JWT can be confused for another. If a particular kind of JWT is subject to such confusion, that JWT can include an explicit JWT type value, and the validation rules can specify checking the type." In #name-use-explicit-typing" target="_blank" rel="nofollow noopener">rfc-editor.org/rfc/rfc8725.ht…
English
0
2
0
0
HTTP APIs
HTTP APIs@http_apis·
"JSON Web Tokens (...) are URL-safe JSON-based security tokens that contain a set of claims that can be signed and/or encrypted.This (...) document updates RFC 7519 to provide actionable guidance leading to secure implementation and deployment of JWTs." In rfc-editor.org/rfc/rfc8725.ht…
English
0
0
1
0
HTTP APIs
HTTP APIs@http_apis·
"The OAuth 2.0 device authorization grant is designed for Internet-connected devices that either lack a browser to perform a user-agent-based authorization or are input constrained" In "OAuth 2.0 Device Authorization Grant" tools.ietf.org/html/rfc8628
English
0
1
0
0