Latest Content

Securing APIs With WSO2 Microgateway

This article focuses on the security aspects of APIs, which is a crucial part of any API management solution. WSO2 API Microgateway, as a solution for exposing microservices as managed APIs, supports a vast array of security features that can be easily configured to suit the API Security requirements of the organization.

What Does It Take to Deliver a Successful API?

Modern businesses are highly consumer driven. Delivering value to our customers is, therefore, our top priority. Making customers' tasks more convenient and efficient should be our primary goal. To do that we need ways to figure out “what” exactly makes our customers more efficient and bring them convenience in their tasks. This requires a lot of trial and error. It also requires us to build and experiment with systems and features to see if these capabilities actually bring significant value to our customers.


What Does It Take to Deliver a Successful API?

현재의 비즈니스 환경은 매우 소비자 주도적입니다. 이러한 상황에서 조직의 최우선 과제는 고객에게 가치를 제공하는 것이며, 가장 중요한 목표는 고객의 업무를 보다 편리하고 효율적으로 개선하는 일입니다. 결국 고객의 업무 효율과 편의를 개선해주는 요소가 “무엇인지”를 파악할 수 있어야 하는데, 여기에는 수많은 시행착오가 따릅니다. 또한 지속적으로 시스템과 기능을 개발하고 이와 관련된 새로운 실험을 반복하여 그 결과물이 실제로 고객에게 유의미한 가치를 제공하는지 확인해야 합니다. 이를 실현하기 위한 노력의 일환으로 조직들은 보다 분산 및 구성이 가능한(compose-able) 엔터프라이즈 아키텍처(enterprise architecture)를 추구하고 있습니다. 이미 익숙한 개념인 마이크로서비스(microservices) 역시 같은 원리로 큰 인기를 끌고 있습니다. 마이크로서비스는 모놀리스(monolith)에 크게 의존하던 전통적인 비즈니스를 훨씬 더 작은 독립적인 단위로 분산시켜 주어, 시스템에 새로운 기능을 보다 빠르게 도입하면서도 시스템의 다른 부분에는 가해지는 영향은 제한할 수 있게 지원합니다.


Introducing WSO2 API Manager 3.1

Today, API-driven business models are increasing in popularity due to the rise of digital transformation in service-based businesses. Business owners are competing to reap the benefits of this trend because they have seen the future of API-driven business models. The API economy has become the next big thing in the business world.


Introducing WSO2 API Microgateway 3.1

WSO2 API Microgateway is a lightweight, developer centric, decentralized, cloud native gateway designed for microservices architecture. As the world is rapidly moving towards microservices, lightweight gateways designed for microservices are becoming more and more popular. This is because microgateways are the key to exposing all microservices as APIs to the outside world and as internal services.


Introducing the WSO2 Identity Server Self-Care Portal

Now more than ever, customers demand immediate results from technology, particularly when dealing with a 24 x 7 global workforce. They often expect simple and easy services that are convenient. These include checking their user accounts online, anytime, anywhere, without making a telephone call or going to a physical location using only a desktop, tablet or mobile phone. Waiting for the help desk to address locked out accounts or password resets ties-up valuable staff with menial tasks and makes users unproductive.


Basic Authentication for API Clients in WSO2 API Manager


Many organizations that embrace an API strategy would have experienced a situation where they had to support Basic Authentication (BasicAuth) for their API clients in addition to OAuth2 due to reasons such as clients’ reluctance to move from BasicAuth to OAuth2. This is even more so a case for 3rd party API clients and partner API clients who can be large in numbers, rather than for 1st party API clients, whom the API product managers have more control over.


Securing WSO2 Enterprise Integrator 6.5 Analytics Using Secure Vault


An application may have numerous configuration files—which are used to define how the application should function. Some of these configuration files may include passwords. Plaintext passwords in configuration files would allow anyone with read access to the configuration files to obtain them. Hence, having plaintext passwords in configuration files is considered a bad practice as explained in this Password Plaintext Storage OWASP article.

