No way for a script or agent to use the API as a person #123

Closed
opened 2026-10-04 17:08:49 -07:00 by rays · 1 comment
Owner

The API takes a session cookie, a proxy's word, or the shared admin token. A script or an agent acting for one person (adding and removing their feeds, reading their items) has to either sign in with a password and carry the cookie, or be given the admin token, which is everyone's admin.

Each person should be able to make named API tokens on their own account, see when each was last used, and revoke one, and send one as Authorization: Bearer . A token acts as its owner and nothing more: an admin's is admin, anyone else's is not. Kept hashed, shown once when made.

The API takes a session cookie, a proxy's word, or the shared admin token. A script or an agent acting for one person (adding and removing their feeds, reading their items) has to either sign in with a password and carry the cookie, or be given the admin token, which is everyone's admin. Each person should be able to make named API tokens on their own account, see when each was last used, and revoke one, and send one as Authorization: Bearer <token>. A token acts as its owner and nothing more: an admin's is admin, anyone else's is not. Kept hashed, shown once when made.
rays added the enhancement label 2026-10-04 17:08:49 -07:00
Author
Owner

Done in 00bd58a, deployed 2026-10-05. Settings makes named tokens (ipx_ and 256 random bits), sent as Authorization: Bearer; only their SHA-256 is kept, in the new api_tokens table, and an unknown or revoked one gets a 401. On the LAN (192.168.1.130:8099) a token works as it is; through the tunnel Cloudflare Access needs a service token beside it, which docs/sso.md describes.

Done in 00bd58a, deployed 2026-10-05. Settings makes named tokens (ipx_ and 256 random bits), sent as Authorization: Bearer; only their SHA-256 is kept, in the new api_tokens table, and an unknown or revoked one gets a 401. On the LAN (192.168.1.130:8099) a token works as it is; through the tunnel Cloudflare Access needs a service token beside it, which docs/sso.md describes.
rays closed this issue 2026-10-04 17:18:23 -07:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: rays/ipx#123