BẢO MẬT API
Xác thực, phân quyền và độ tin cậy của yêu cầu
Mỗi thao tác phải nêu rõ định danh client, ngữ cảnh người dùng, scope, liên kết tenant/RP và cơ chế bảo vệ transport/yêu cầu.
01
Các đường xác thực
| Path | Use | Controls |
|---|---|---|
| OAuth2 client credentials | Service-to-service | Client ID, scope, audience and rotation |
| OIDC user context | User-delegated flows | Subject, authentication context and consent |
| mTLS | High-assurance service identity | Certificate chain, SAN and revocation |
| Signed request | Selected channels | Timestamp, nonce, body digest and key ID |
| WebAuthn assertion | Signer approval | Challenge, origin, RP ID, credential and counters |
02
Mô hình scope
| Scope | Purpose |
|---|---|
| signing.request | Create/read signing requests |
| signing.approve | Submit/verify signer approval |
| signing.activate | Issue or consume signature activation |
| signing.execute | Execute approved signature operations |
| evidence.read | Read evidence and verification results |
| evidence.renew | Request evidence renewal |
| admin.providers | Manage approved CA/provider routes |
03
Quy tắc xử lý bí mật
- No access tokens in URLs or logs.
- Credential IDs and signer identifiers masked outside the trust boundary.
- SAD values short-lived, purpose-bound and never returned to unauthorized clients.
- mTLS private keys stored in approved key protection.
- Webhook secrets rotated and versioned.
