Wiki source code of Data Exchange

Last modified by Waria on 2026/07/23 10:11

Hide last authors
Waria 19.2 1 {{container}}
2 {{container layoutStyle="columns"}}
3 (((
CarlijnKokkeler 16.1 4 In this section, we’ll examine how eMagiz manages data exchange between applications and integrations, focusing on security considerations for each method. eMagiz supports three main integration patterns: Messaging, API Gateway, and Event Streaming. We'll explore the security measures associated with each pattern, including options like OpenID Connect, OAuth2.0, and access control lists. By understanding these patterns and their specific security configurations, you'll be better equipped to protect data and ensure secure interactions across your integrations.
marijn 1.1 5
Erik Bakker 2.1 6 Should you have any questions, please get in touch with [[academy@emagiz.com>>mailto:academy@emagiz.com]].
marijn 1.1 7
8 == 1. Prerequisites ==
9
Erik Bakker 6.1 10 * Expert knowledge of the eMagiz platform
marijn 1.1 11
12 == 2. Key concepts ==
13
Erik Bakker 10.1 14 This microlearning focuses on security considerations when exchanging data via the platform.
marijn 1.1 15
Erik Bakker 10.1 16 * Each pattern comes with generic and specific checks and balances to ensure security is taken care of when exchanging data.
marijn 1.1 17
Erik Bakker 10.1 18 == 3. Data Exchange ==
marijn 1.1 19
Erik Bakker 10.1 20 Because eMagiz provides the integration between two or more applications via the eMagiz platform, the point at which the data is interchanged between application and integration is a critical part of the integration in terms of security.
21 Within eMagiz, there are three main integration patterns a user can configure to support their business case most optimally. First, this section will look at all three integration types and specify the security measures.
marijn 1.1 22
Erik Bakker 10.1 23 === 3.1 Messaging ===
marijn 1.1 24
Erik Bakker 10.1 25 Messaging is the most flexible option of the three; therefore, a wide range of options is available within eMagiz to secure the connections.
26 eMagiz offers users the tools to set up integrations and end-points securely. eMagiz supports well-known market standards, including:
marijn 1.1 27
Erik Bakker 10.1 28 * OpenID Connect
29 * WS-Security
30 * API Keys in combination with HTTPS/SSL
31 * SOAP Authentication
32 * OAuth2.0
33 * Basic Authentication
marijn 1.1 34
Erik Bakker 10.1 35 This way, each connection between the application and the integration (end-point) can be adequately secured and gives the flexibility to confer with the external application which method best suits their needs.
marijn 1.1 36
Erik Bakker 10.1 37 === 3.2 API Gateway ===
marijn 1.1 38
Waria 21.1 39 The front-end of your API Gateway can be secured using a structure with users and permissions. The security of the backend of the API Gateway can be customized just as for messaging. Confer with your external party how the backend needs to be secured.
marijn 1.1 40
Waria 21.1 41 eMagiz offers multiple authentication methods for API Gateway users: OAuth 2.0, Basic Auth and API Key. These can be configured per user. This means that you can choose the strongest authentication method supported by the consuming application.
42
43 For OAuth 2.0 eMagiz hosts an authorization server per customer environment which functions as the IDP (identity provider). By communicating with this IDP via the OAuth2.0 protocol, a check is done every time a client calls a specific operation to see whether that client can access the API Gateway and has sufficient rights to access the operation.
44
45 Although users can authenticate using OAuth 2.0, Basic Auth, or an API Key, eMagiz validates all requests through the same authorization infrastructure. Basic Auth and API Key credentials are translated internally to OAuth-based authorization, ensuring that user permissions are evaluated consistently regardless of the chosen authentication method. This centralizes authorization logic and reduces the risk of differences in security behavior between authentication mechanisms.
46
47 To learn more about configuring API security and user permissions check out the [[API Gateway Crash Course>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course API Gateway.WebHome||target="blank"]].
Erik Bakker 9.1 48
Erik Bakker 10.1 49 === 3.3 Event Streaming ===
50
51 Within the Event Streaming solution, eMagiz provides Event Streaming users, and topics can be created.
52 Access to a topic within a cluster is governed by an Access Control List (ACL). This ACL links users to a topic and defines what the user can do on a topic (consume, produce, both).
53
54 Only users with sufficient rights in the Deploy phase of eMagiz can add users, and topics and change the ACL entries specific to the Event Streaming cluster.
55
56 Apart from producing or consuming data on specific topics based on the ACL, users also need a valid Keystore (containing the key and cert generated automatically) and a valid truststore (containing the CA certificate of the event streaming cluster) to produce or consume data.
57
58 These are all security measures to prevent third parties from unauthorized access to the data stored on the topics.
59
Erik Bakker 11.1 60 For more information on how this precisely can be configured via the eMagiz platform, please check the following [[microlearning>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course Event Streaming.crashcourse-eventstreaming-user-management||target="blank"]].
Erik Bakker 10.1 61
62 === 3.4 General ===
63
64 Regardless of the selected pattern for your solution, it would be best if you always considered that you only exchange relevant information with the external party. This means you should consider both headers as the payload you need to exchange with the external party. This is particularly interesting for any communication via HTTP gateways as they hold functionality to send all message headers as HTTP headers and vice versa.
65
etorken 12.1 66 == 4. Key takeaways ==
marijn 1.1 67
Erik Bakker 10.1 68 * Each pattern comes with generic and specific checks and balances to ensure security is taken care of when exchanging data.
69 * When you are not careful, you might share too much information with external parties.
marijn 1.1 70
etorken 12.1 71 == 5. Suggested Additional Readings ==
marijn 1.1 72
Erik Bakker 18.1 73 * [[Fundamentals (Navigation)>>doc:Main.eMagiz Academy.Fundamentals.WebHome||target="blank"]]
74 ** [[eMagiz Security Guide (Explanation)>>doc:Main.eMagiz Academy.Fundamentals.fundamental-emagiz-security-guide||target="blank"]]
dfirdausy 13.1 75 * [[Crash Course (Menu)>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.WebHome||target="blank"]]
76 ** [[Crash Course API Gateway (Navigation)>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course API Gateway.WebHome||target="blank"]]
Waria 20.1 77 *** [[API User Management (Explanation)>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course API Gateway.crashcourse-api-gateway-user-management||target="blank"]]
CarlijnKokkeler 14.1 78 ** [[Crash Course Event Streaming (Navigation)>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course Event Streaming.WebHome||target="blank"]]
79 *** [[User Management - Event Streaming (Explanation)>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course Event Streaming.crashcourse-eventstreaming-user-management||target="blank"]]
CarlijnKokkeler 15.1 80 * [[Data exchange (Search Result)>>url:https://docs.emagiz.com/bin/view/Main/Search?sort=score&sortOrder=desc&highlight=true&facet=true&r=1&f_space_facet=0%2FMain.&f_type=DOCUMENT&f_locale=en&f_locale=&f_locale=en&text=data+exchange||target="blank"]]
Waria 19.2 81 )))
82
83 (((
84 {{toc/}}
85 )))
86 {{/container}}
87 {{/container}}