A method and system for providing a first network resource with secure but
limited access to a second network resource. A method embodying the
invention includes receiving, from a client, a request to access the
first resource. The client is then directed to an authorization service.
The authorization service generates an authorization ticket and provides
the authorization ticket to the first resource. On behalf of the first
resource, the authorization ticket is presented to the second resource
with a request to access the second resource. The request is granted only
if it can be verified that the authorization ticket was generated by a
source trusted by the second resource.