Input Validation: Because Users Are Creative, and Attackers Are More Creative
There is a special kind of optimism that exists in software development.
Read article: Input Validation: Because Users Are Creative, and Attackers Are More Creative12 articles tagged Apigee.
There is a special kind of optimism that exists in software development.
Read article: Input Validation: Because Users Are Creative, and Attackers Are More CreativeA long time ago, I was doing integration architecture work in the land of Enterprise Service Buses (ESBs) and API Gateways. Think IBM WebSphere DataPower and Apigee — I like to remember Apigee the way it was before it was integrated into GCP. After we had designed and built the ESB, we moved on to…
Read article: A Vendor DMZ PatternNot so long ago, someone asked me for a list of all the Apigee and API Management related material I have written. The following was my response. The recipient suggested that I post this; so, here we go.
Read article: A Brief Summary of All Things Apigee and API Management that I Have WrittenThis post was originally published as “Demo: Apigee Edge OAuth2 Debugging” on the Apigee Blog.
Read article: Demo: Apigee Edge OAuth2 DebuggingThis post provides a detailed view of what happens when my example API Proxy that integrates Apigee Edge and a Third-Party Identity Provider for OAuth2 use cases. The setup instructions are available here.
Read article: Apigee Edge and Third-Party Identity Provider Integration — Detailed ViewThis blog post summarizes the details of how to deploy and configure the the Apigee Edge OAuth2 example that I put together. This example will use the OAuth2 Authorization Code Grant and Refresh Token Grant to demonstrate how OAuth2 can be used with Apigee Edge in a real-world application.
Read article: Apigee Edge OAuth2 and Third-Party Identity ProvidersThis post was originally published as “How to Submit Tokens to an API Provider, Pt 2” on the Apigee Blog.
Read article: How To Submit Your Security Tokens to an API Provider, Pt. 2This post was originally published as “How to Submit Tokens to an API Provider, Pt 1” on the Apigee Blog.
Read article: How To Submit Your Security Tokens to an API Provider Pt. 1This post was originally published as “Design Principles for Seamless User Authentication” on the Apigee Blog.
Read article: Design Principles for Seamless User AuthenticationThis post was originally published as “Keeping Your APIs Secure for Multiple User Types” on the Apigee Blog.
Read article: Keeping Your APIs Secure for Multiple User Types