[Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-03-30 Thread Sajith Kariyawasam
When discussing about possible ways of implementing SSO for API Manager 3.0 (C5) we came up with following two approaches, In API Manager 3.0, store, publisher and admin apps will be Oauth clients, which works with access tokens. 1. Access token retrieved via SAML grant - When a user requests a r

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-03-30 Thread Joseph Fonseka
On Thu, Mar 30, 2017 at 3:36 PM, Sajith Kariyawasam wrote: > > 2. Access token retrieved via Authorization code grant > +1 for the second approach I guess you are suggesting to use OpenID Connect ? I guess the only additional requirement is the user info endpoint [1] Regards Jo [1] http://ope

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-03-31 Thread Farasath Ahamed
On Thursday, March 30, 2017, Sajith Kariyawasam wrote: > > When discussing about possible ways of implementing SSO for API Manager > 3.0 (C5) we came up with following two approaches, > In API Manager 3.0, store, publisher and admin apps will be Oauth clients, > which works with access tokens. >

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-03-31 Thread Bhathiya Jayasekara
On Sat, Apr 1, 2017 at 1:39 AM, Farasath Ahamed wrote: > > > On Thursday, March 30, 2017, Sajith Kariyawasam wrote: > >> >> When discussing about possible ways of implementing SSO for API Manager >> 3.0 (C5) we came up with following two approaches, >> In API Manager 3.0, store, publisher and ad

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-04-01 Thread Farasath Ahamed
On Sat, Apr 1, 2017 at 11:27 AM, Bhathiya Jayasekara wrote: > > > On Sat, Apr 1, 2017 at 1:39 AM, Farasath Ahamed > wrote: > >> >> >> On Thursday, March 30, 2017, Sajith Kariyawasam wrote: >> >>> >>> When discussing about possible ways of implementing SSO for API Manager >>> 3.0 (C5) we came up

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-04-04 Thread Harsha Thirimanna
On Apr 1, 2017 10:37 PM, "Farasath Ahamed" wrote: On Sat, Apr 1, 2017 at 11:27 AM, Bhathiya Jayasekara wrote: > > > On Sat, Apr 1, 2017 at 1:39 AM, Farasath Ahamed > wrote: > >> >> >> On Thursday, March 30, 2017, Sajith Kariyawasam wrote: >> >>> >>> When discussing about possible ways of

Re: [Architecture] [APIM] [C5] Single sign on support in API Manager 3.0

2017-04-20 Thread Asela Pathberiya
On Wed, Apr 5, 2017 at 9:04 AM, Harsha Thirimanna wrote: > > > On Apr 1, 2017 10:37 PM, "Farasath Ahamed" wrote: > > > > > > On Sat, Apr 1, 2017 at 11:27 AM, Bhathiya Jayasekara > wrote: > >> >> >> On Sat, Apr 1, 2017 at 1:39 AM, Farasath Ahamed >> wrote: >> >>> >>> >>> On Thursday, March 30,