Resource links from July meeting (API security and Scotch Box)

9 views
Skip to first unread message

Chris Spruck

unread,
Jul 20, 2016, 9:43:06 AM7/20/16
to Atlanta PHP, Atlanta PHP Meetup
Hi everyone!

Below are the resource links from our talks at the July meeting - Anthony Green on API Security and Garrett Rappaport on Scotch Box VMs.

Here are the API resource links from Anthony:

OWASP RESTful API
https://www.owasp.org/index.php/REST_Security_Cheat_Sheet

OWASP HTTP Headers
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project#tab=Headers

OAuth
http://oauth.net/

OpenID Connect
http://openid.net/connect/

JWT
https://jwt.io/

Let’s Encrypt TLS Certificate Project
https://letsencrypt.org/

Anthony also offered a PDF of his slides with his speaker notes added, but we won't post it openly, as he's also giving the talk at http://connect.tech here in Atlanta in October (and submitted it elsewhere). Please email me *directly only* (ch...@atlantaphp.org) if you'd like a copy of this PDF.

And Garrett's links for Scotch Box resources:

https://gist.github.com/syntacticNaCl/32dd38ad9a19adebf546e06329ec9beb - reference links

Thanks!
Chris

Chris Spruck

unread,
Jul 20, 2016, 12:20:48 PM7/20/16
to Atlanta PHP
One quick addition regarding a great tool for working with APIs. Tunc, a new group member, mentioned the following to me:

When it comes to working with APIs, there is a tool I use which has been a life (time) saver in many ways. I wish I had mentioned it during the meeting and shared it with the group. It's called Postman. https://www.getpostman.com/ It helps isolate the API commands with the rest of code. I usually approach my development in two steps and Postman helps me make sure I have the API part setup properly, before I proceed with my own code.

If anyone has any other good suggestions for tools, tutorials, etc. feel free to respond to this thread.

Chris

Dave Mednick

unread,
Jul 22, 2016, 9:33:59 PM7/22/16
to AtlantaPHP Discussions and Job Postings, php-336-...@meetup.com
Have been using the Chrome ARC extension for a while. It's a great testing tool and very flexible.

Reply all
Reply to author
Forward
0 new messages