Re: [Architecture] [BAM] [Security] Securing REST API

2015-02-04 Thread Anjana Fernando
On Wed, Feb 4, 2015 at 5:15 AM, Prabath Siriwardena prab...@wso2.com wrote: If you say Basic Auth is easy - then there is no difference in using OAuth too:-) Basically the resource owner credentials grant type was introduced in OAuth to migrate clients from Basic/Digest authentication

Re: [Architecture] Support per API (ESB) logging configuration

2015-02-04 Thread Sagara Gunathunga
On Wed, Feb 4, 2015 at 2:27 PM, Maninda Edirisooriya mani...@wso2.com wrote: Hi Sagara, Ratha and Miyura, Can you please mention the products that are already shipping with this feature? (APIM 1.8.0 or ESB 4.9.0 or what?) We have faced this requirement. Above PR is not yet merged :) Kasun

Re: [Architecture] CDM Policy Management Approach

2015-02-04 Thread Prabath Ariyarathna
Hi Dilan I have a small suggestion on your proposal about the policy levels. You have proposed three policy(User, Platform and Role) levels here and each policy level has predefined priority which cannot be changed accordingly. According to your mail, you are going to apply the same approach to

Re: [Architecture] Support per API (ESB) logging configuration

2015-02-04 Thread Maninda Edirisooriya
Hi Sagara, Ratha and Miyura, Can you please mention the products that are already shipping with this feature? (APIM 1.8.0 or ESB 4.9.0 or what?) We have faced this requirement. Thanks. *Maninda Edirisooriya* Senior Software Engineer *WSO2, Inc.*lean.enterprise.middleware. *Blog* :