How do I implement login in a RESTful web service?

As S.Lott pointed out already, we have a two folded things here: Login and authentication

Authentication is out-of-scope here, as this is widely discussed and there is common agreement. However, what do we actually need for a client successfully authenticate itself against a RESTful web service? Right, some kind of token, let’s call it access-token.

Client) So, all I need is an access-token, but how to get such RESTfully?
Server) Why not simply creating it?
Client) How comes?
Server) For me an access-token is nothing else than a resource. Thus, I’ll create one for you in exchange for your username and password.

Thus, the server could offer the resource URL “/accesstokens”, for POSTing the username and password to, returning the link to the newly created resource “/accesstokens/{accesstoken}”.
Alternatively, you return a document containing the access-token and a href with the resource’s link:

<access-token
  id="{access token id goes here; e.g. GUID}"
  href="https://stackoverflow.com/accesstokens/{id}"
/>

Most probably, you don’t actually create the access-token as a subresource and thus, won’t include its href in the response.
However, if you do so, the client could generate the link on its behalf or not? No!
Remember, truly RESTful web services link resources together in a way that the client can navigate itself without the need for generating any resource links.

The final question you probably have is if you should POST the username and password as a HTML form or as a document, e.g. XML or JSON – it depends… 🙂

Leave a Comment

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)