Skip to content
Discussion options

You must be logged in to vote

Right, in a typical 3-tier setup, the Leaf API runs on the App Server, and user HTTP requests are reverse-proxied to the API:

Leaf uses a standard RESTful API, and most endpoints by and large are protected and only accept requests if a given HTTP request includes an AccessToken (example: /api/cohort/count). There is one and only one API.

AccessTokens are generated for a user only after they first are authenticated and retrieve a UserToken, after which they can request an AccessToken, which is valid for only 6 minutes.

In other words, the flow is:

  1. User requests a UserToken (i.e., authenticates), which is successful if and only if the request contains expected shibboleth headers with user…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@artgoldberg
Comment options

@artgoldberg
Comment options

@ndobb
Comment options

Answer selected by artgoldberg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants