[aerogear-dev] Auth-Token: how to ensure one token is used from only one device ?
matzew at apache.org
Thu Sep 27 02:26:41 EDT 2012
using the Auth-Token to get access to protected resources / endpoints
(after doing a login) works fine!
I am wondering how to avoid that one token is used on different
devices? (e.g. when somebody is 'stealing' the token).
I did sign-in to the app, using the browser and got the following
token => db5d16da-a1e5-48d9-a2fd-e39e36e835bc
Now I was able to issue a get request against the endpoints, by using
the same token, from different 'devices':
- iOS test case
NOTE: we don't need a solution now, since I know you guys are busy
with some demo work - but just want to run that 'issue' by this list
More information about the aerogear-dev