1. APIs Rule!2. Designing Security for APIs3. Securing APIs with Transport Layer Security (TLS)4. OAuth 2.0 Fundamentals5. Edge Security with an API Gateway6. OpenID Connect (OIDC)7. Message Level Security with JSON Web Signature8. Message Level Security with JSON Web Encryption9. OAuth 2.0 Profiles10. Accessing APIs via Native Mobile Apps11. OAuth 2.0 Token Binding12. Federating Access to APIs13. User Managed Access14. OAuth 2.0 Security15. Patterns and A. The Evolution of Identity B. OAuth 1.018: C. How Transport Layer Security D. UMA Evolution20. E. Base64URL F. Basic/Digest Authentication 22: G. OAuth 2.0 MAC Token Profile
An excellent book, no doubts. Everything is explained in a clear and concise way. Step by step of the different processes (encryption, serialization, ...) makes it even easier to understand and recap. Plenty of nice examples, in Java, that go beyond Hello World. Topics are up to date for 2021. Really an excellent but still user friendly book for anyone interested in APIs, Security, Microservices and JSON.
Ótimo overview sobre o assunto, passando por princípios básicos de segurança de APIs até os mais diversos fundamentos do OAuth 2.0.
Talvez pelo tipo do conteúdo e, até porque não estamos aplicando no dia-a-dia todos os cenários apresentados, é um livro que pode ser bem maçante de ser lido de ponta-a-ponta.