Looking for the right way: Spring Social + Spring RESTful API + Spring WebApp + Mobile Clients
Asked Answered
T

1

8

I have a RESTful API built with Spring 3.1, using Spring Security as well. I have a web application, also a Spring 3.1 MVC application. I am planning to have mobile clients accessing my REST API. So my API is the central place to authenticate, get data served from, etc.. It all makes sense so far.

Now what I cannot wrap my head around is how to add Spring Social in an easy and smart way. How did you do it? Did you maybe only move the ConnectionRepository to the API? Or did you have the API do it all? I want to prevent double-authorization for each client-technology by all means (preventing double-authorization meaning userA connects to facebook in the webapp, and then starts using our mobile client and should NOT be asked to connect to facebook again just b/c userA is using a different client).

Thanks for sharing your thoughts!

Tetherball answered 7/5, 2013 at 1:56 Comment(1)
So far, I found some hints here: porterhead.blogspot.com/2013/01/…Tetherball
T
2

The solution we use it to secure our rest-webservices using spring security, with a cookie based remember me service. This uses well documented traditional spring-security techniques.

We then plugged in spring-social to our system, which then simply logs in the user as normal using spring secruity. The social api looks up the, for example, facebook id in your db table, if it finds existing connection logs the user in using their account on your system (and can redirect to sign up page etc).

I suggest breaking down the question into more specific areas.

Tierza answered 12/2, 2014 at 9:5 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.