ããã¯ãšã³ãéçºã®ã³ã³ããã¹ãã§ã¯ãèªèšŒã¯ã API ãããŒã¿ããŒã¹ããµãŒããŒãªã©ã®ä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšããŠãããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ããŸãã¯ã·ã¹ãã ã®èº«å ã確èªããããã«æ¡çšãããéèŠãªã»ãã¥ãªãã£å¯Ÿçã§ããèªèšŒã¯ãããŒã¿ãšãµãŒãã¹ã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§ã確ä¿ããããã«äžå¯æ¬ ã§ããããã«ã¯ãäžæ£ã¢ã¯ã»ã¹ã鲿¢ããæ£åœãªãŠãŒã¶ãŒãšã·ã¹ãã ã®ã¿ãä¿è·ããããªãœãŒã¹ãšå¯Ÿè©±ã§ããããã«ããããã®äžé£ã®æè¡ãšããã»ã¹ãå«ãŸããŸãã
èªèšŒã®äžå¿ååã® 1 ã€ã¯ãè³æ Œæ å ±ã䜿çšããããšã§ããè³æ Œæ å ±ã¯ããŠãŒã¶ãŒåãAPI ããŒãé»åã¡ãŒã« ã¢ãã¬ã¹ãªã©ã®äžæã®èå¥åãšããŠãŒã¶ãŒãŸãã¯ãŠãŒã¶ãŒã«é¢é£ä»ããããç§å¯ã³ã³ããŒãã³ã (ãã¹ã¯ãŒããããŒã¯ã³ãæå·åããŒãªã©) ã§æ§æãããŸããã·ã¹ãã ãèªèšŒããã»ã¹ã¯ããŠãŒã¶ãŒãŸãã¯ã·ã¹ãã ããããã®è³æ Œæ å ±ãããã¯ãšã³ã ãµãŒãã¹ã«æäŸãããšéå§ãããŸããæ¬¡ã«ãããã¯ãšã³ãã¯ãåä¿¡ããè³æ Œæ å ±ããéåžžã¯å®å šãªããŒã¿ããŒã¹ãŸã㯠ID ããã³ã¢ã¯ã»ã¹ç®¡ç (IAM) ãœãªã¥ãŒã·ã§ã³ã«ä¿åãããŠãããä¿åãããŠããæ¿èªæžã¿è³æ Œæ å ±ã®ã»ãããšæ¯èŒããŸããäžèŽããå Žåãããã¯ãšã³ã ãµãŒãã¹ã¯ãŠãŒã¶ãŒãŸãã¯ã·ã¹ãã ã«ã¢ã¯ã»ã¹ãèš±å¯ãããŠãŒã¶ãŒãŸãã¯ã·ã¹ãã ãç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããããããŒã¿ãååŸãŸãã¯å€æŽãããã§ããããã«ããŸãã
ææ°ã®ããã¯ãšã³ãéçºã§ã¯ãããŸããŸãªãããã³ã«ãæšæºã䜿çšããŠèªèšŒãå®è£ ãããããšããããããŸããäžè¬çã«äœ¿çšããããããã³ã«ã«ã¯ãAPI ãžã®ã¢ã¯ã»ã¹ãæ¿èªããããã®äºå®äžã®æšæºã§ãã OAuth ãå«ãŸããŸãã OpenID ConnectãOAuth 2.0 äžã«æ§ç¯ããã人æ°ã® ID ã¬ã€ã€ãŒã SAML ã¯ãåœäºè éã§èªèšŒããã³èªå¯ããŒã¿ã亀æããããã®å ç¢ãª XML ããŒã¹ã®ãããã³ã«ã§ããããšãã°ã AppMaster ã¯ãSwagger (OpenAPI) ããã¥ã¡ã³ããæ¡çšããŠãçæãã Webãã¢ãã€ã«ãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ã®èªåçæãµãŒããŒendpointsã®èªèšŒããã³ãã®ä»ã®ã»ãã¥ãªãã£åŽé¢ã®ç®¡çãæ¯æŽããŸãã
ããã¯ãšã³ãéçºã§äœ¿çšã§ããèªèšŒã¡ã«ããºã ã®äž»ãªã¿ã€ãã¯æ¬¡ã®ãšããã§ãã
- åºæ¬èªèšŒ: ããã¯æãåçŽãªèªèšŒåœ¢åŒã§ããããŠãŒã¶ãŒã®è³æ Œæ å ±ããªã¯ãšã¹ã ããããŒå ã® Base64 ã§ãšã³ã³ãŒããããæååãšããŠéä¿¡ãããŸãããã ããåºæ¬èªèšŒã¯çèŽãäžéè (MITM) æ»æã«å¯ŸããŠè匱ã§ãããããæ©å¯æ§ã®é«ãã¢ããªã±ãŒã·ã§ã³ã«ã¯æšå¥šãããŸããã
- ããŒã¯ã³ããŒã¹ã®èªèšŒ: JSON Web ããŒã¯ã³ (JWT) ãäžéæãªã¢ã¯ã»ã¹ ããŒã¯ã³ãªã©ã®ããŒã¯ã³ã¯ãèªèšŒãæåãããšçæãããåŸç¶ã®ãªã¯ãšã¹ãã«å«ããããŸããããŒã¯ã³ããŒã¹ã®èªèšŒã¯ããã®ã·ã³ãã«ããã¹ããŒãã¬ã¹ãªæ§è³ªã忣ã·ã¹ãã ãã·ã³ã°ã« ãµã€ã³ãªã³ (SSO) ã·ããªãªãžã®é©åæ§ã«ãã奜ãŸããŠããŸãã
- API ããŒããŒã¹ã®èªèšŒ: API ããŒã¯ã¢ããªã±ãŒã·ã§ã³ãŸãã¯ãŠãŒã¶ãŒã«å²ãåœãŠãããäžæã®èå¥åã§ãããéåžžã¯ç¹å®ã® API ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããã«å©çšãããŸãã API ããŒã¯ãæå¹æéãé·ãæå¹æéããªããããããŒã¯ã³ããŒã¹ã®èªèšŒãããå®å šæ§ãäœããçé£ãæªçšã®å±éºæ§ãé«ããªããŸãã
- å€èŠçŽ èªèšŒ (MFA): MFA ã¯ããŠãŒã¶ãŒãç¥ã£ãŠãããã® (ãã¹ã¯ãŒã)ããŠãŒã¶ãŒãæã£ãŠãããã® (ããŒããŠã§ã¢ ããŒã¯ã³ãŸãã¯æºåž¯é»è©±ïŒãããã³ãŠãŒã¶ãŒãã®ãã®ïŒçäœèªèšŒïŒã MFA ã¯ãäžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ãå€§å¹ ã«è»œæžãããããæ©å¯ããŒã¿ãã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãä¿è·ããããã«åŒ·ãæšå¥šãããŸãã
ããã¯ãšã³ã ãµãŒãã¹ã®å®å šæ§ã確ä¿ããã«ã¯ãèªèšŒããã»ã¹èªäœä»¥å€ã«ããä»ã®ã»ãã¥ãªãã£å¯Ÿçãšãã¹ã ãã©ã¯ãã£ã¹ãéèŠã§ããããã«ã¯ã宿çãªè³æ Œæ å ±ã®ããŒããŒã·ã§ã³ã転éäžããã³ä¿åäžã®ããŒã¿ãä¿è·ããããã®æå·åã®äœ¿çšãæªæã®ããã¢ã¯ãã£ããã£ãŸãã¯ç°åžžãªã¢ã¯ãã£ããã£ã®ç£èŠãæå°ç¹æš©ã®ååã匷å¶ããããã®åŒ·åãªã¢ã¯ã»ã¹å¶åŸ¡ã®å®è£ ãªã©ãå«ãŸããŸãã
ããã¯ãšã³ãéçºã«ãããèªèšŒã®éèŠãªåŽé¢ã¯ãã¢ããªã±ãŒã·ã§ã³ ã¢ãŒããã¯ãã£å šäœã®ä»ã®ã³ã³ããŒãã³ããšã®ã·ãŒã ã¬ã¹ãªçµ±åã§ãã AppMaster ãã¢ãã€ã«ãWebãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ã®äœæãæ¯æŽããno-codeãã©ãããã©ãŒã ã§ãããåçåãããèªèšŒå®è£ ãæäŸãããœãªã¥ãŒã·ã§ã³ã®äžäŸã§ãã AppMasterã䜿çšãããšãäŒæ¥ã¯ããã¯ãšã³ã ãœãªã¥ãŒã·ã§ã³çšã®ããŒã¿ ã¢ãã«ãããžãã¹ ããžãã¯ãREST APIãããã³ WSS endpointsãèŠèŠçã«äœæã§ããŸããããã«ãããã¢ããªã±ãŒã·ã§ã³ ãšã³ã·ã¹ãã å ã§ãããå æ¬çã§ä¿å®å¯èœãªèªèšŒããã³ãµãŒãã¹ç®¡çã¢ãããŒããå¯èœã«ãªããŸãã
å®å šãªèªèšŒã¡ã«ããºã ãå°å ¥ããããšã¯ãæ©å¯ããŒã¿ãšã·ã¹ãã ãªãœãŒã¹ãä¿è·ããã ãã§ãªãããŠãŒã¶ãŒéã®ä¿¡é Œãè²ãã®ã«ã圹ç«ã¡ãçžäºæ¥ç¶ããŸããŸãé²ã仿¥ã®äžçã§ç¶ç¶çãªæé·ãšæåã確å®ã«ãããããããããã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠæãéèŠã§ããããã¯ãšã³ãéçºã³ã³ããã¹ãã«ãããèªèšŒã®éèŠæ§ãšå©çšå¯èœãªããŸããŸãªæè¡ãçè§£ããããšã§ãéçºè ã¯ãå¢å€§ããç¯å²ã®ãµã€ããŒã»ãã¥ãªãã£è åšã«å¯Ÿæã§ããå ç¢ã§å®å šãªã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ã§ããŸãã