Hi Everyone, here are my 2 cents on this topic.
OAuth is a framework which will really help users to take advantage of it without getting into the complexity of Authentication and Authorization. Yes, it will be great features if we have in AwareIM. This will not only opens the door of more possibilities where I can imagine running multiple AwareIM apps/3rd party apps and they can call each other API with the same authentication/authorization flow.
Currently, We are using JWT(JSON web token) in all our API for authentication much before version 8.0, when consuming REST API not exists. Example: every time when a new user register/login himself system create a new unique token which is used for calling API. A Token is saved on server and client side (native mobile) and later used every time for every request which authenticates and custom development we have a capability to control the flow of data.
There are still some drawbacks or limitation when we exposed REST API under AwareIM.
Below are the few of them
- All attributes values get exposed if we want to return object limited attributes only. This is major issue which has other problems if you have large business object.
- Multiple responses cannot be paged
- All are GET API, POST API is recommended for sending data from client to server.
- Not able to send credential data under using Authorization Header.
- Not able to upload a document or any file today.
- When there are multiple records and API request does not have any data, No way to define response.
There are still few tricks which help we can to achieve responses from AwareIM API.