eclipse-thingweb / node-wot

A fast and extensible framework to connect any device with your browser and backend applications
https://thingweb.io
Other
165 stars 79 forks source link

HTTP security flexibility #889

Open egekorkan opened 1 year ago

egekorkan commented 1 year ago

Currently, the TD allows quite a lot of flexibility for HTTP BasicAuth and API Key (others too but let's start here?). I was talking about this with @danielpeintner on Wednesday and also supervising @ms499 who is doing an analysis of the security in general. This was talked briefly in the TD call yesterday since we need implementations of these features if we want to keep them in the spec.

I will put some initial analysis that should be extended and possibly better organized:

I am not sure if this is the best place to discuss this and think of what we should do in the future. This issue can be seen more as a discussion I think.

relu91 commented 1 year ago

Note point 2 is important for our dev meeting we should prioritize this issue. I'm also creating a label to find issues related to TD assertions.