Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7086331
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 28, 20262026-05-28T07:32:11+00:00 2026-05-28T07:32:11+00:00

I’m using RESTeasy framework to develop my web service. I’ve managed to set up

  • 0

I’m using RESTeasy framework to develop my web service. I’ve managed to set up BASIC authentication, and it is working properly now. Of course, I do plan to use SSL on top of this.

The process is simple (and please read something about HTTP basic Auth if you don’t know what this is about):

  1. Every request is intercepted by a method which analyzes the request header.
  2. This header is decoded and the username and password are extracted.
  3. The method then queries the database to check if the username and password match.
  4. If they match the request proceeds, if they don’t, a 401 code is returned.

With this approach, every request implies a request to the database, due to the stateless nature of REST (and HTTP itself).

My question is: Is it possible to don’t query the database on every authenticated request?

Possible hints: Some mechanism using cookies?

This question is technologically agnostic.


Just as a side note:

I really feel that there is very little information on this REST authentication matter. It’s just OAuth, OAuth, OAuth… If we don’t want to authenticate 3rd party applications, information is scattered everywhere and there aren’t any concrete examples, like there are using OAuth.
If you have any good advises regarding Authentication in REST WebServices, I would love to hear them.

Thank you.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-28T07:32:12+00:00Added an answer on May 28, 2026 at 7:32 am

    The answer ended up to be cache.

    In my particular case I was using RESTeasy as a REST framework and Google App Engine as the Application Server. It wasn’t hard to find out that GAE has support to memcache.

    If you’re using Objectify (you really should; it’s awesome), it’s even easier. Just annotate your entity classes with @Cached. This procedure is illustrated here.

    Objectify supports another kind of cache in a session Object. In other words, as long your Objectify object is instantiated, it can provide your objects even without using memcache (This is good because in GAE there quotas for using memcache, although they are cheaper than the datastore ones). I strongly advise you to read Objectify’s good practices in their wiki.

    As a final note, I’ll consider using Digest authentication instead of Basic. It seems much more secure. The fact that the password never travels through the network really reliefs me.

    I hope that this SO question was useful to someone and for those who helped me: thank you. 🙂

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

That's pretty much it. I'm using Nokogiri to scrape a web page what has
I'm new to using the Perl treebuilder module for HTML parsing and can't figure
link Im having trouble converting the html entites into html characters, (&# 8217;) i
I have a jquery bug and I've been looking for hours now, I can't
this is what i have right now Drawing an RSS feed into the php,
I'm using v2.0 of ClassTextile.php, with the following call: $testimonial_text = $textile->TextileRestricted($_POST['testimonial']); ... and
Seemingly simple, but I cannot find anything relevant on the web. What is the
We're building an app, our first using Rails 3, and we're having to build
I'm parsing an RSS feed that has an ’ in it. SimpleXML turns this
We are using XSLT to translate a RIXML file to XML. Our RIXML contains

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.