Tracking API: Allow setTokenAuth() to be an admin token, not only the Super User #2302

mattab opened this Issue Apr 12, 2011 · 1 comment

1 participant

Piwik Open Source Analytics member

Super User token is very secret. The Tracking API should allow for more flexibility and allow any "admin" token for the site being tracked.

For performance, we don't want to query the DB on each Tracking API request. So we can cache in the Tracker cache files the list of all allowed admin token_auth and check against this list.

Piwik Open Source Analytics member

(In [4417]) Fixes #2302 Now, setTokenAuth on the Tracking API can accept the Super User token_auth or any 'admin' user token_auth (the token are cached in the tracker cache file, which is now flushed when users or permissions are changed)

@mattab mattab added this to the Piwik 1.3 milestone Jul 8, 2014
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment