web services - Embedding security details in a SOAP message -


i working @ client have developed web service includes security context detail (like user credentials or saml token alternative) inside wsdl definition of service.

is normal practice embed authorization credentials inside soap message? expect authentication details handled outside of message , should not passed inside message.

can possibly point me documentation describes best practices around this?


Comments

Popular posts from this blog

basic authentication with http post params android -

vb.net - Virtual Keyboard commands -

css - Firefox for ubuntu renders wrong colors -