API tokens a person makes for scripts and agents to act as them (#123)
The API took a session cookie, a proxy's word or the shared admin token, so a script or an agent working for one person had to sign in with their password and carry the cookie, or be given the admin token. Settings now makes named tokens, ipx_ and 256 random bits, sent as Authorization: Bearer. A token is its owner and no more. Only its SHA-256 is kept, in the new api_tokens table, with when it was made and last used; it is shown once and revoked from the same list. An unknown or revoked one gets a 401 rather than falling through to a cookie. Cloudflare Access still stands in front of the tunnel, so from outside a token needs an Access service token beside it; docs/sso.md says how. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
14
docs/sso.md
14
docs/sso.md
@@ -233,5 +233,19 @@ Set `auto_create_users = false` once everyone who should have an account has one
|
||||
proxy vouching for an unknown name is logged and refused. Make people ahead of time instead, with
|
||||
the exact name the header will carry.
|
||||
|
||||
## API tokens for scripts and agents
|
||||
|
||||
Anyone can make API tokens for their own account in Settings. A token is sent as
|
||||
`Authorization: Bearer ipx_...` and acts as the person who made it, admin only if they are. Only
|
||||
its SHA-256 is kept; it is shown once, when made, and revoked there too.
|
||||
|
||||
Through the tunnel, Cloudflare Access turns a request with no Access sign-in towards Authentik
|
||||
before ipx sees it, so a token alone does not get in that way. On the LAN, `http://192.168.1.130:8099`
|
||||
takes it directly. From outside, make an Access service token, add a Service Auth policy for it to
|
||||
the `ipodderx` application, and send `CF-Access-Client-Id` and `CF-Access-Client-Secret` beside the
|
||||
`Authorization` header: Access lets the request through, vouches for no name, and ipx takes the
|
||||
API token as who is asking. Do not bypass Access for `/api/*` instead; the token would then be the
|
||||
only thing between the internet and the API.
|
||||
|
||||
See also [users.md](users.md) for what several people share, [configuration.md](configuration.md)
|
||||
for every `[web]` key, and [cli.md](cli.md) for the `ipx user` commands.
|
||||
|
||||
Reference in New Issue
Block a user