authentication - Is it nessesarry to send credentials on every single request to MVC Web Api? -


i create first restfull web service chose mvc web api "provider". after reading authentication little confused.

my requirements on call url of webservice want client authenticated, except sign in url.

i understand flow way: after client signed, webservice returns authenticationtoken client have store, , send server on every request in headers. token stored on webservice?

i confused @ flow of actions have implement if want avoid users pass login parameters on every single request.

typically how works user's authentication token stored in cookie. once authenticate user, create 'session' them server side. there 'session token' corresponds session.

when user signs in, create new session them. send them new cookie. every future request make contain cookie. use cookie identify user's session. it, can draw username, etc.

it sounds want .net state management (https://msdn.microsoft.com/en-us/library/75x4ha6s(v=vs.140).aspx). should using this, , see how can apply current needs.

in long run, once you've got proper user session tokens, not need send credentials every request. session token enough identity user upon every request make.


Comments

Popular posts from this blog

How to connect android app to App engine -

gcc - MinGW's ld cannot perform PE operations on non PE output file -

php - display validation error message next to the textbox in codeigniter -