Implementing authorization in web applications and APIs - Dominick Baier & Brock Allen

  Рет қаралды 39,211

NDC Conferences

NDC Conferences

Күн бұрын

Пікірлер: 18
@davidlester6673
@davidlester6673 3 жыл бұрын
Your arguments are so narrow minded. Yes attribute based role authorisation checks with magic strings will be a nightmare to code and maintain, thats a given. How about using permission based attributes with enums. An method will only perform one operation for a single purpose and hence will have one permission. So typed permissions with attributes would be ideal. Lucky thats the way my authorization has worked for some considerable time.
@consciousmi4842
@consciousmi4842 Жыл бұрын
Is it possible to have those projects for learning purpose ?
@vivekgowda1576
@vivekgowda1576 3 жыл бұрын
Hi Sir, Thanks for the video. I have setup the identity server 4 with .net core 3.1 Every thing is working fine but the thing is i need configure Redis caching for server side. Can you help me out(Redis server is up and run in my local system )
@simplelife8722
@simplelife8722 3 жыл бұрын
Guys! Thanks a ton for giving me a different perspective to approach AC in my ORG... I am definitely gonna use the ideas shared by you in this amazing presentation. Thank You! Good Luck :)
@vahidakbarirad1761
@vahidakbarirad1761 6 жыл бұрын
plz I need source code.It can take me out of hell.
@adriancooke7310
@adriancooke7310 7 жыл бұрын
Hi Is this nuget package ready to ship and use. In the slide I don't see any reference to a how to get started section. Is this stuff bleeding edge? Is their a gitter channel?
@raviormetal1653
@raviormetal1653 6 жыл бұрын
They just showed how to implement authorization (when using identity provider) and concluded that there is no generalized framework for this since most businesses need very specific implementations.
@temitopemagbagbeola5204
@temitopemagbagbeola5204 6 жыл бұрын
I think what might be of more benefit is including the token to permissions(aka AuthorizationEngine) feature in identity server.That way clients(especially spa's) and api's can get permissions on user login to implement separate authorization as required.
@davevanboal3669
@davevanboal3669 7 жыл бұрын
Thank you Dominick and Brock! This video will help focus our Authorization Architectural Direction. We already have something like this that can be extended to implement some of the additional concepts you cover. This video will help further our discussion. Amusing conclusion near the end. :-)
@OhMaegs
@OhMaegs 6 жыл бұрын
A very helpful video! The only question I still have is, do they pass the token from the api to the authorization service or do they just pass the username? Is it necessary to use security in the authorization service ?
@TheVincent0268
@TheVincent0268 5 жыл бұрын
Is the used sample code still available?
@technogeek48
@technogeek48 7 жыл бұрын
First - Also, really helpful; thanks!
@stanleytoles33
@stanleytoles33 6 жыл бұрын
i LOVE Dominick's accent haha
@raviormetal1653
@raviormetal1653 6 жыл бұрын
You mean a german speaking english ^^
@alexgarcia8311
@alexgarcia8311 6 жыл бұрын
It looks to me that they are mixing business rules with actual authorization. The idea is good. But it seems to be very easy to start having business logic in the custom policies' logic.
@Prod-23
@Prod-23 6 жыл бұрын
Depends on your domain I guess. But Authorisation may well be related to business logic. I don't see a problem with that if authorisation is in fact dependent on business rules how else are you going to do it?
Microservices and Rules Engines - a blast from the past - Udi Dahan
52:48
Win This Dodgeball Game or DIE…
00:36
Alan Chikin Chow
Рет қаралды 39 МЛН
Nastya and balloon challenge
00:23
Nastya
Рет қаралды 70 МЛН
Life hack 😂 Watermelon magic box! #shorts by Leisi Crazy
00:17
Leisi Crazy
Рет қаралды 21 МЛН
Bjarne Stroustrup: C++ | Lex Fridman Podcast #48
1:47:13
Lex Fridman
Рет қаралды 1 МЛН
IdentityServer for ASP.NET Core 2 - Brock Allen & Dominick Baier
54:51
NDC Conferences
Рет қаралды 29 М.
Vertical Slice Architecture - Jimmy Bogard
1:02:01
NDC Conferences
Рет қаралды 101 М.
Web Apps can’t really do *that*, can they? - Steve Sanderson
58:24
NDC Conferences
Рет қаралды 167 М.
What are Digital Signatures? - Computerphile
10:17
Computerphile
Рет қаралды 336 М.
Identity Server 4 with Angular and ASP.NET Core - Ben Cull
1:02:36
NDC Conferences
Рет қаралды 20 М.
Domain Driven Design: The Good Parts - Jimmy Bogard
58:39
NDC Conferences
Рет қаралды 220 М.
ASP.NET Core Full Course For Beginners
3:43:18
Julio Casal
Рет қаралды 233 М.
Andy Morrell - ADHD in a Development Environment
26:06
Qudos Recruitment
Рет қаралды 38
Win This Dodgeball Game or DIE…
00:36
Alan Chikin Chow
Рет қаралды 39 МЛН