I'm development a SOAP web service version 1.1 in Java.
I have the following situation:
- there's a secured channel with ssh;
- customers don't have login credentials (they don't have username and password);
- when a customer opens an account is generated a session token;
- when a customer make requests is validated by their session token;
- when a customer account is open only him or employee is allowed to close the account (session timeout can't exist);
what is the best way to implement security in this situation? should i generate the session tokens or there is already apis/frameworks to do that job? Does STS (开发者_JAVA百科Security Token Service) able to do it without requirements of login credentials?
the purpose of that is to invoke the web service in android application.
 
         
                                         
                                         
                                         
                                        ![Interactive visualization of a graph in python [closed]](https://www.devze.com/res/2023/04-10/09/92d32fe8c0d22fb96bd6f6e8b7d1f457.gif) 
                                         
                                         
                                         
                                         加载中,请稍侯......
 加载中,请稍侯......
      
精彩评论