<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Power BI Rest API and HTTPS in Developer</title>
    <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Rest-API-and-HTTPS/m-p/291744#M8575</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not very familar with network security stuff like https and certificates and how the content of a request will be encrypted.&lt;BR /&gt;Following scenario:&lt;BR /&gt;I would like to use the Power BI REST API in my Windows App to show some "filtered" reports. The Windows App applies the "right" filter regarding the user whitch is currently logged in.&lt;BR /&gt;I have to make sure that there is no way to capture the access token I'm using with the API calls. I think about "man in the middle attacts" or something like this.&lt;/P&gt;&lt;P&gt;Can anybody confirm that the access token can not be captured?&lt;BR /&gt;Is this possibly dependend on the client sdk I'm using? (Javascript, C#, ..)&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;BR /&gt;Marco&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2017 16:08:03 GMT</pubDate>
    <dc:creator>mwotruba</dc:creator>
    <dc:date>2017-10-27T16:08:03Z</dc:date>
    <item>
      <title>Power BI Rest API and HTTPS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Rest-API-and-HTTPS/m-p/291744#M8575</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not very familar with network security stuff like https and certificates and how the content of a request will be encrypted.&lt;BR /&gt;Following scenario:&lt;BR /&gt;I would like to use the Power BI REST API in my Windows App to show some "filtered" reports. The Windows App applies the "right" filter regarding the user whitch is currently logged in.&lt;BR /&gt;I have to make sure that there is no way to capture the access token I'm using with the API calls. I think about "man in the middle attacts" or something like this.&lt;/P&gt;&lt;P&gt;Can anybody confirm that the access token can not be captured?&lt;BR /&gt;Is this possibly dependend on the client sdk I'm using? (Javascript, C#, ..)&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;BR /&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 16:08:03 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Rest-API-and-HTTPS/m-p/291744#M8575</guid>
      <dc:creator>mwotruba</dc:creator>
      <dc:date>2017-10-27T16:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Power BI Rest API and HTTPS</title>
      <link>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Rest-API-and-HTTPS/m-p/292345#M8589</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/24526"&gt;@mwotruba&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm not very familar with network security stuff like https and certificates and how the content of a request will be encrypted.&lt;BR /&gt;Following scenario:&lt;BR /&gt;I would like to use the Power BI REST API in my Windows App to show some "filtered" reports. The Windows App applies the "right" filter regarding the user whitch is currently logged in.&lt;BR /&gt;I have to make sure that there is no way to capture the access token I'm using with the API calls. I think about "man in the middle attacts" or something like this.&lt;/P&gt;
&lt;P&gt;Can anybody confirm that the access token can not be captured?&lt;BR /&gt;Is this possibly dependend on the client sdk I'm using? (Javascript, C#, ..)&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;BR /&gt;Marco&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/24526"&gt;@mwotruba&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;I'm not an expert on network, however it seems that the &lt;A href="https://security.stackexchange.com/questions/8145/does-https-prevent-man-in-the-middle-attacks-by-proxy-server" target="_self"&gt;HTTPS already can prevent man in the middle attacks&lt;/A&gt;. There was risk because Power BI used to use the accesstoken for embedding service and the accesstoken was a plaintext in the embedding web page. Now &lt;A href="https://msdn.microsoft.com/en-us/library/mt784614.aspx" target="_self"&gt;Embedded token&lt;/A&gt; has been applied, which is limited to specific report/dashboard with view/edit permissions. The risk has been reduced to the minimum in my opinion.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 07:04:23 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Developer/Power-BI-Rest-API-and-HTTPS/m-p/292345#M8589</guid>
      <dc:creator>Eric_Zhang</dc:creator>
      <dc:date>2017-10-30T07:04:23Z</dc:date>
    </item>
  </channel>
</rss>

