[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Authenticated Access to RSS



Scott Loftensness and I were discussing something off-list, and it got me
thinking about how to provide authenticated access to syndication when using
a desktop RSS-reader such as Radio or Headline Viewer. Here's the challenge.
In an intranet environment, once can restrict access to RSS files at the
network layer. That is, using firewalls and VPNs one can control who can
reach the HTTP server that delivers the files.

But what about an extranet environment? Suppose you want to publish weblogs
and their associated RSS files, but restrict them to customers, vendors and
other partners? It's easy to use basic authentication (username/password) to
limit access to the HTML renderings of the weblogs, but what about the XML?
For instance, do any of the RSS viewers support authentication? Are there
any considerations within the various RSS specs themselves for
authentication? (They're just XML, so I imagine not.)

Any other suggestions on how one would handle this challenge?

(Cross-posted to http://blogbook.weblogger.com.)

     ...doug

Doug Kaye
doug@rds.com