IMO, it should take the simplest approach:
- I create an account on the sync server (this can be an application account)
- Use HTTPS with basic authentication and pass the credentials on authentication.
HTTPS would be fine as sync is typically an async and not performance-sensitive operation.
I'd make it optional if I mark a feed as "secure".
/kzu
--
Daniel Cazzulino | Developer Lead | XML MVP | Clarius Consulting |
+1 425.329.3471