My take on RESTful authentication
facundoolano.wordpress.com
facundoolano.wordpress.com
One thing (perhaps rightfully) missing is auth in the tls/ssl layer. Client certs do work, pre-shared keys sadly do not really work. And I don't know what happened with tls-srp:
I'm not confident implementing SRP in Javascript provides any real advantage. From a trust standpoint, if you're going to use authentication code pushed to you, you're already all-in. The reason I advocate SRP on the web (via a browser implementation) is because 1) people reuse passwords and 2) I think it's become clear we can't trust web services, even big names, to handle passwords securely. We also can't trust corporations, public access machines and schools etc. not to strip SSL wholesale. We also shouldn't give bad actors the opportunity to put subtle backdoors in to authentication code of compromised servers.
If you're on an entirely secure network, and you don't mind users seeing user name + password in the url then it might not be a problem.
As far as I understood, the [MEAN.io](http://mean.io) stack implements OAuth2 like this - at the 'cost' of having two MVCs: one on the server side to deal with the authentifiction, 404 and 500, and the AngularJS one on the client side.
I hoped that there was an easier way to deal with the whole scenario, but obviously that is a good one.