Mastering Web Services Security - part 2

chúng tôi giả định rằng các giao diện trước đó đã được thực hiện trên một máy chủ ứng dụng có chứa J2EE, CORBA, COM +, hoặc các thành phần NET. Một sự tương tác điển hình sẽ đi một cái gì đó như thế này: Một khách hàng đầu tiên là xác thực , | Overview of Web Services Security 21 For this scenario we assume that the preceding interfaces have been implemented on an application server containing J2EE CORBA COM or .NET components. A typical interaction would go something like this A customer is first authenticated to and ePortal then gets a list of products and prices from eBusiness using getProducts and getPrice. The customer then places an order for products into his or her account which ePortal requests from using placeOrder. Sometime later the customer settles the orders with a credit card number which ePortal requests from by calling settleOrder. Users tttt Visitors Customers Members Staff Figure eBusiness Web Service interfaces. 22 Chapter 1 Scenario Security Requirements The Web Service security policies that we define in later chapters are based on the business requirements for this example. Generally it s the combination of ePortal and eBusiness security mechanisms that enforces the overall business requirements for our example. We describe the business requirements for each class of user below. Visitors. To entice new customers ePortal permits visitors who are unauthenticated users to browse the site. Visitors are permitted very limited access. Visitors may See the product list but not their prices. Register to become a customer. Visitors may create an Account which turns the visitor into a Customer. Customers. Most users accessing ePortal are customers who are permitted to order regular products. Customers may See the product list and prices for regular products but not the prices for special products which are only offered to members. Place delete and settle pay for orders. A customer may not delete his or her Account however and must ask someone on the ePortal staff to perform this task. ePortal wants to make it difficult for customers to remove their affiliation with the company. Members. If approved by ePortal some customers may become members. .

Bấm vào đây để xem trước nội dung
TỪ KHÓA LIÊN QUAN
TÀI LIỆU MỚI ĐĂNG
13    143    1    25-06-2024
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.