In ESRI documentation, when we talk about token and security, their suggest to use SSL protocol for make a request to token service present in arcgis server. In the GET method the request is encrypted and the comunication between client and server is safe. The problem is when we transtimt sensitive data in the request like have to do for obtain a token. We don't want to have sensitive data (f.e. password) sitting around somewhere in cleartext. Here's a few places where request string is exposed as cleartext:[INDENT]
- Server side logs
- History caches in browsers
- Bookmarks
- Bugs in the application/browser (f.e. HTTP referrer leakage)
[/INDENT]The best you can do today is to POST sensitive data to a server over HTTPS. To do this with Flex, or other languages that want to use the getToken service, I show you an idea for make this with the POST method.I hope this help someone, the code is also attacched.
<?xml version="1.0" encoding="utf-8"?>
<mx:Application xmlns:mx=""
pageTitle="Example - ArcGIS API for Flex connecting to a protected dynamic AGS service"
import com.esri.ags.layers.ArcGISDynamicMapServiceLayer;
import mx.rpc.http.HTTPService;
import mx.utils.StringUtil;
private function init():void {
var baseMap:ArcGISDynamicMapServiceLayer = new ArcGISDynamicMapServiceLayer(/*myBaseMapUrl*/);
// user and password data can come from to a flex form
// for my test I force it to a known user and password present in my security store (in my case ActiveDirectory)
public function RequestToken(username:String, password:String):void {
var http:HTTPService = new HTTPService();
http.addEventListener( ResultEvent.RESULT, tokenResultHandler );
http.addEventListener( FaultEvent.FAULT, faultHandler );
// constants
var rootURL:String = Application.application.url.substr(0,Application.application.url.indexOf("/",8));
var expir:int = 1440;
// parameters for the request
var param:Object = {
"request" : "gettoken",
"username": username,
"password": password,
"clientid" : "ref."+ rootURL,
"expiration" : expir
// prepare the httpService object for send the request
http.url = "https://myAGSTokenService/arcgis/tokens?tokens"; // fake parameter ?tokens for start the process of token generation
http.method = "POST"; // set POST method for not have problem in cache and logs
http.resultFormat = "text";
http.request = param; // set parameters for the request
function faultHandler(event:FaultEvent):void {;
function tokenResultHandler(event:ResultEvent):void {
var theToken:String = StringUtil.trim(event.result.toString()); // trim the generated token for surprise...
private function loadProtectedMaps(token:String):void {
var protectedMap1:ArcGISDynamicMapServiceLayer = new ArcGISDynamicMapServiceLayer(/*urlToYourServiceRest1*/);
protectedMap1.token = token;
var protectedMap2:ArcGISDynamicMapServiceLayer = new ArcGISDynamicMapServiceLayer(/*urlToYourServiceRest2*/);
protectedMap2.token = token;
<mx:Label text="This is an example with a base map and two protected service with token service. The token is dinamically requested to the token service in post method and SSL connection for security issue. Have a nice day" fontSize="14"/>
<esri:Map id="map" />