NOTE
How to Design Authentication and Authorization
Authentication, authorization, and credentials; common techniques; and how authentication and authorization are integrated into a microservice architecture.
This is a historical learning note and may contain outdated or incomplete understanding.
1. What Are Authentication and Authorization
- Authentication: the identity of the current user, solving the question “Who am I?”
- Authorization: what kinds of identities are allowed to access certain resources, solving the question “What can I do?”
- Credential: the foundation of authentication and authorization, a medium that marks a visitor’s identity or rights.
2. Why Authentication and Authorization Are Needed
Security.
3. Authentication and Authorization Technologies
3.1. Authentication Technologies
3.1.1. HTTP Authentication

Disadvantage: Base64 can only be called encoding, not encryption.
Scenario: management backends such as routers.
3.1.2. HMAC (AK/SK) Authentication
The message authentication code in Security.md.
Disadvantage: the key must not be leaked.
Scenario: authentication between servers.
3.1.3. OpenID Connect
3.2. Authorization Technologies
3.2.1. OAuth
3.3. Credential Technologies
3.3.1. Cookie Session
3.3.2. JWT
4. How a Microservice Architecture Integrates Authentication and Authorization
4.1. Authentication
How to Design User Registration and Login.md

4.2. Authorization
Use OAuth2.
4.3. Credentials
Cookie Session.

Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub