Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow completely restricting /api/ endpoints to those with authorization #1879

Closed
wlach opened this issue May 29, 2019 · 0 comments · Fixed by #1926
Closed

Allow completely restricting /api/ endpoints to those with authorization #1879

wlach opened this issue May 29, 2019 · 0 comments · Fixed by #1926
Assignees

Comments

@wlach
Copy link
Contributor

wlach commented May 29, 2019

For the internal mozilla use case, we would like to be able to restrict any access to /api/ to those clients with either a token or a valid session. Currently we rely on openidc auth for these endpoints but this approach doesn't work well with the ajax approach we use inside the notebook.

For this to be useful, we need #1755 first.

/cc @robotblake

@wlach wlach assigned wlach and unassigned wlach Jun 4, 2019
@jezdez jezdez self-assigned this Jun 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants