web services - Embedding security details in a SOAP message -
i working @ client have developed web service includes security context detail (like user credentials or saml token alternative) inside wsdl definition of service.
is normal practice embed authorization credentials inside soap message? expect authentication details handled outside of message , should not passed inside message.
can possibly point me documentation describes best practices around this?
Comments
Post a Comment