Laravel - How to make the token authentication in one service, if the login is validated in another service?

Viewed 67

I have two APIs. One includes all of the informations about the users, such as register and login functionalities. The other has all of the information about organizations, including search and requests adding images, videos and documents of those organizations. The reason to make this in two separate APIs is that the users API has a much bigger scalability as it is more likely to have a bigger number of users than the number of organizations in the organizations API, but if they both grow significantly, it could be a problem to have all of those informations in the same API.

I am using Laravel to develop the backend of these APIs.

I need to use an account registered and authenticated with a token in the users API to make a search in the organizations API, which only an authenticated user could make, how can I connect the APIs?

How can I get the user token created in the users API and use it in the organizations API?

Idea I though about creating a table with the id, token and expiration date of the token to be kept in the organizations API. So when the user logs in, the token is passed to the organization API, that will then have access to the token when it needs it. Would it work? How to achieve it?

1 Answers

Issue set of keys like api-key and salt-key, your api-key would act as a user identification key (Something similar to username) and your module generate a signature by encrypting the data being sent with salt.

on your service 1

  • Sort the data in a specific order
  • Encrypt the total data with a Salt key to generate signature.
  • Post the raw and signature (without salt key)

Example Code:

$data['name']  = 'xxx';
$data['mail']  = 'yyy';
$data['age']   = 'zzz';

//sort the data in some order
ksort($data);

//create a piped delimited raw signature with the data
$raw_data = '';
foreach($data as $key => $value)
{
     $raw_data = $raw_data .'|'. $value ;
}

$decrypted = $newEncrypter->decrypt( $data);
$newEncrypter = new \Illuminate\Encryption\Encrypter('salt-key');
$data['signature'] = $newEncrypter->encrypt( $data);

on your service 2

  • Receive the data
  • Eliminate the signature
  • Sort the data in the same order
  • Re-encrypt it with the salt key (you would need to fetch this from db or .env)
  • Validate if the received and generated signature is in sync. Example Code:
//we will grab the signature as received_signature to compare later and would unset from the data.
$compare['received_signature']  = $request->input('signature');
$data   = $request->input();
unset($data['signature');

//sort the data in some order
ksort($data);

//create a piped delimited raw signature with the data
$raw_data = '';
foreach($data as $key => $value)
{
     $raw_data = $raw_data .'|'. $value ;
}

$newEncrypter = new \Illuminate\Encryption\Encrypter('salt-key');
$compare['generated_signature'] = $newEncrypter->encrypt( $data);

if($compare['generated_signature'] != $compare['received_signature'])
{
    //take some action like opening ticket or email notification
    die();
}

Outcome If the signature is in sync, you're good to go and if not you might need to ignore it.

Related