DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium

A developer is building a RESTful API that will be consumed by various client applications. To ensure that only authorized clients can access specific resources, the API needs to implement a robust authorization mechanism. After a client has been authenticated, what is the most appropriate method for the API to determine if the client has the necessary permissions to perform a requested action on a given resource?

  1. APrompting the user for their credentials on every API call.
  2. BValidating a JSON Web Token (JWT) containing scopes or roles.
  3. CRequiring a static API key for each request.
  4. DChecking the client's IP address against a whitelist.
Show answer & explanation

Correct answer: B. Validating a JSON Web Token (JWT) containing scopes or roles.

JSON Web Tokens (JWTs) are commonly used for authorization. Once a client is authenticated, an Authorization Server issues a JWT containing claims about the user or client, such as roles or scopes. The API can then validate this JWT and inspect its claims to determine if the client is authorized for the requested action, providing a stateless and scalable solution.

Why the other options are wrong

  • A. Prompting for credentials on every call is poor user experience and inefficient, typically handled by an initial authentication and subsequent token-based authorization.
  • C. Static API keys are typically for client authentication, not granular authorization, and can be difficult to manage securely at scale.
  • D. IP whitelisting is not flexible enough for dynamic clients and doesn't provide granular authorization per user/client.

JWT for Authorization

JSON Web Tokens (JWTs) can carry claims (e.g., roles, scopes) that an API uses to determine if an authenticated client has permission to access a resource or perform an action.

  • Stateless authorization.
  • Claims define permissions.
  • API validates token signature and claims.
  • Issued after successful authentication.

Memory trick: JWT claims access; others are too simple or cumbersome.

More Application Deployment and Security questions