Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6709449
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T07:53:00+00:00 2026-05-26T07:53:00+00:00

What is the best way to do authentication and authorization in web services? I

  • 0

What is the best way to do authentication and authorization in web services?

I am developing a set of web services, requiring role based access control.
Using metro – SOAP, simple java without EJBs.

  • I want to Authenticate the user just one time, using username and
    password, to be matched against a data base. In the subsequent calls.
  • I would like to use some kind of session management. Could be some
    session id, retrieved to the client at login, to be presented in all
    calls.

So Far:

  • Read authentication using a database – but I want application level validation;
  • Read application authentication with jax-ws – but i don’t want to do the authentication mechanism every time;

  • I think I can use a SOAP Handler, to intercept all the messages, and do the authorization control in the hander, using some session identifier token, that comes with the message, that can be matched against an identifier saved in the data base, in the login web method.

EDIT:

I still have some questions:

  • How to know the name of the web method being called?
  • What kind of token should I use?
  • How to pass this token between calls?

EDIT 2

Because of @ag112 answer:

I’m using Glassfish.

I use WS-Policy and WS-Security to encrypt and sign the messages. Using Mutual Certificate Authentication. I would like to complement this message level security between applications, with the authentication and authorization for the users also in message level.

I am just developing the services, and I don’t know almost nothing the clients, just that they could be created in different languages.

At this point I think the most important thing is to do what ever I need to do to authenticate and authentication the users, I the most easy way to be implemented for the client applications.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T07:53:00+00:00Added an answer on May 26, 2026 at 7:53 am

    After all the help, I create this answer to simplify, and summarize all the ideas that was discussed.

    The questions has 2 requisites:

    • Message level security;
    • One time authentication.

    With ag112 help, this is hard to do, or to elegant in any way. So here are to conclusions:

    • For message level security send the user
      credentials every time (place it in SOAP header);
    • For one time authentication use transport level security, and do a
      session management.

    I prefer the first one, because the message level was the biggest requisite.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm looking for the best way to provide authorization, authentication, and auditing to web
I'm wondering about the best way to structure authentication/authorization in my app. I want
What is the best way to use preemptive basic http authentication using HttpUrlConnection. (Assume
What is the best way to control user access to a controller. I have
what is the best way to implement AA mechanism ( authorization and Authentication )
I'm making my first web app (python+webpy+mongodb). What's the best way to make authentication
What is the best way to use live id authentication with azure based asp.net
What is the best way to access a Rails 3 REST-ful web service, developed
Please suggest me the best authentication way to implement in the scenario mentioned below:
What's the best way to authenticate and track user authentication state from page to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.