{"id":1369,"date":"2020-02-28T12:46:30","date_gmt":"2020-02-28T12:46:30","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/publishedserviceauthentication\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"publishedserviceauthentication","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/publishedserviceauthentication","title":{"rendered":"Published Rest and Web services should require authentication"},"content":{"rendered":"\n<p>When publishing a web or REST service, it should not be consumable by everybody (anonymous). Instead a Mendix (web service) user should be created for each consumer of this service.  Having a fine-grained user for authentication has the following advantages:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>it is easy to identify which user caused a change in your application (traceability)<\/li><li>it makes it possible to constrain access on the user (role) level<\/li><li>it is easy to log the usage of your service and monitor where requests are coming from<\/li><\/ul>\n\n\n\n<p>For more information check <a href=\"https:\/\/docs.mendix.com\/howto\/security\/best-practices-security#5-applying-authentication-on-services\">https:\/\/docs.mendix.com\/howto\/security\/best-practices-security#5-applying-authentication-on-services<\/a><\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"375\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-29-1024x375.png\" alt=\"\" class=\"wp-image-1371\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-29-1024x375.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-29-980x359.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-29-480x176.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"778\" height=\"436\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-30.png\" alt=\"\" class=\"wp-image-1372\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-30.png 778w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-30-480x269.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 778px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"779\" height=\"435\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-31.png\" alt=\"\" class=\"wp-image-1373\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-31.png 779w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-31-480x268.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 779px, 100vw\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"374\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-32-1024x374.png\" alt=\"\" class=\"wp-image-1374\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-32-1024x374.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-32-980x358.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-32-480x175.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n","protected":false},"featured_media":0,"parent":96,"menu_order":23,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-1369","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1369"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1369"}],"version-history":[{"count":2,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1369\/revisions"}],"predecessor-version":[{"id":1375,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1369\/revisions\/1375"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Constants should not be used for sensitive information","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/sensitiveconstant","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/245"}],"prev":[{"title":"Microflow should only have permissions if used from a page","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowunneccesarypermissions","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/594"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1369"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=1369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}