DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
A web application uses OAuth 2.0 for user authentication and authorization. After a user successfully logs in through an identity provider, the client application receives an access token. The developer needs to ensure that this access token is used securely when making API calls to a protected resource server. Which HTTP header is the standard and most secure way to transmit this token?
- AX-Auth-Token
- BContent-Type
- CCookie
- DAuthorization
Show answer & explanationAnswer & explanation
Correct answer: D. Authorization
The Authorization HTTP header, specifically with the 'Bearer' scheme, is the standard and most secure method for transmitting OAuth 2.0 access tokens to protected resource servers.
Why the other options are wrong
- A. X-Auth-Token is a custom header and not the standard for OAuth 2.0, making it less interoperable and potentially less secure if not handled correctly.
- B. Content-Type specifies the media type of the resource, not authentication credentials.
- C. Cookies are typically used for session management, not for directly transmitting Bearer tokens in API calls, especially for stateless REST APIs.
OAuth 2.0 Bearer Token Usage
OAuth 2.0 Bearer tokens are used by client applications to access protected resources on behalf of a user, typically transmitted via the HTTP Authorization header.
- Represents authorization granted to the client.
- Transmitted in the 'Authorization: Bearer <token>' HTTP header.
- Should be protected against interception (e.g., via HTTPS).
Memory trick: Authorization Bearer: The standard for secured server access.