Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Allow restricting feeds to "userless" api keys

    Scheduled Pinned Locked Moved Support
    2 Posts 2 Posters 8 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Stephen.Schaff
      last edited by

      API Keys have the ability to emulate a user. This allows restricting the feeds that an API Key can connect to (very useful).

      I find I am submitting a lot of tickets to my System Admins to get network users made, just so I can make an API Key have limited permissions.

      In reality the user does not need to exist anywhere except logically in ProGet. The connection uses the API Key, which then uses the user's permissions in ProGet to restrict their permissions. The user's password is never used and the user is never logged in.

      I would like to request that a way be made that I could restrict an API Key to specific feeds without needing to create a user in my domain.

      One possible way of doing this is to make an option for the name of the Key to be a "user" on the permissions page. That way it can have permission restrictions.

      NOTE: I think this would be easier if I was not using active directory, as I could just make the user in Proget. But with active directory as my user provider, I cannot just add a user.

      1 Reply Last reply Reply Quote 0
      • atrippA Offline
        atripp inedo-engineer
        last edited by gdivis

        Hi @Stephen-Schaff ,

        Yes, this can be a little bothersome. Actually this is something that we're considering for v6, to mostly replace the "impersonation" feature:

        • Allow on Feeds:
          • [feed1, feed2, «group1»]
        • Feed Permission:
          • View/Download
          • Publish/Push
          • Delete/Overwrite

        The "username" would still be there, but mostly for "personal api keys".

        Thanks,
        Alana

        1 Reply Last reply Reply Quote 0

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        • 1 / 1
        • First post
          Last post
        Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation