# Sirix rest api.. security

**URL:** <https://sirix.discourse.group/t/sirix-rest-api-security/32>\
**Category:** Uncategorized\
**Created:** [August 24, 2019, 7:45pm UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32 "2019-08-24T19:45:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwin](https://yyz2.discourse-cdn.com/free1/user_avatar/sirix.discourse.group/jwin/32/9_2.png) [@jwin](https://sirix.discourse.group/u/jwin)\
**Post date:** [August 24, 2019, 7:45pm UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32/1 "2019-08-24T19:45:11Z")

</div>

Hi,

regarding sirix-rest-api …class Auth

Is there a way to avoid the keycloak request on every sirix api request ?

Regards  
Jörg

---

<div class="post-metadata">

**Author:** ![Jojo](https://yyz2.discourse-cdn.com/free1/user_avatar/sirix.discourse.group/jojo/32/6_2.png) [@Jojo](https://sirix.discourse.group/u/Jojo)\
**Post date:** [August 25, 2019, 8:58am UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32/2 "2019-08-25T08:58:49Z")

</div>

Hi Jörg,

I just had a quick look into the Vert.x implementation, but if the token is already there it seems to just check if it’s expired and then returns a future with an AccessToken object (OAuth2AuthProviderImpl).

Thanks for asking 🙂 Did you have trouble setting up SirixDB with Keycloak?

Have a great sunday 🙂

kind regards  
Johannes

---

<div class="post-metadata">

**Author:** ![jwin](https://yyz2.discourse-cdn.com/free1/user_avatar/sirix.discourse.group/jwin/32/9_2.png) [@jwin](https://sirix.discourse.group/u/jwin)\
**Post date:** [August 25, 2019, 10:46pm UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32/3 "2019-08-25T22:46:37Z")

</div>

The setup instructions could be more polished, I think… but everything in the keycloak-vertx setup worked perfectly.  
I verified that the keycloak server is not contacted while vertx has the valid token, as expected.  
Thanks for the info.

The routes /login and /[database] need some work on their responses, hopefully I can create a PR the next days.

Keep up the nice work… whats next ?  
Horizontal scaling and replication would definitely be a great feature.

J

---

<div class="post-metadata">

**Author:** ![johannes](https://yyz2.discourse-cdn.com/free1/user_avatar/sirix.discourse.group/johannes/32/7_2.png) [@johannes](https://sirix.discourse.group/u/johannes)\
**Post date:** [August 26, 2019, 2:43pm UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32/4 "2019-08-26T14:43:30Z")

</div>

Cool, thank you very much 🙂

Yeah, I think after releasing 1.0 I want to look into horizontal scaling and replication 🙂

Most probably with a transaction-log stored in Apache BookKeeper for replicating resources through a single writer and asynchronous readers. I think it also provides stuff like read your own writes and so on. Plus quorum-based writes…

---

<div class="post-metadata">

**Author:** ![johannes](https://yyz2.discourse-cdn.com/free1/user_avatar/sirix.discourse.group/johannes/32/7_2.png) [@johannes](https://sirix.discourse.group/u/johannes)\
**Post date:** [August 26, 2019, 3:04pm UTC](https://sirix.discourse.group/t/sirix-rest-api-security/32/5 "2019-08-26T15:04:50Z")

</div>

BTW: Thanks so much 🙂

looking also forward to your PR 🙂
