MyServers Permission
-
Hi @noah,
I agree that this would be a good feature.
I've been doing some thinking on it...
What if we could restrict an S2S server to only being able to call a specific set of scripts? That way you would be in full control as to the scope of the API that you are making available.
Would that work for your use case?
Paul.
-
hi. @Paul-Winterhalder
yes, permissions to call specific scripts and access control for Services and Operations regarding the generally provided functions are required.
For example, there may be management tools that call specific scripts and use certain functions (CloudData...),
and there may be administrators who only manage items.
If possible, each API Key should be a function with permissions tailored to the situation.Let me give you an example. A company utilizes a mix of office and remote work. While the internal network can be protected to some extent by IP ranges, it is difficult to identify specific IPs because multiple operators work from home. Therefore, it is currently somewhat difficult to handle this situation using only IPs.