Setting permissions on Apigee BAAS -
What is the best way to set permissions on an object in Apigee BAAS entities, such a collection is such that users who Can also make them, and others can read them? There may be a case of being able to edit everything for the administrator.
I asked a similar question here that was around the acquisition of Ape ID / Incognito which would be necessary to update the permission to make calls, but I was thinking that from the mobile app like this There is no best practice about talking about or not.
My initial idea will still be the service callout (not sure how Apigee-127 is that the previous question will be different for BAAS directly for the service callout because I think 127 like I used to use the edge console Instead of writing my episodes in node. JS), but I do not know whether it is easy in case of securing all institutions in specific institutions created by specific institutions. I think I can add one from the perspective of an app created by the column, but it can not prevent anyone from killing BS directly and retrieving this information until a user needs a login token Permission is not granted at any entity level on the basis of.
Is it possible to secure BAAS in such a way that only calls from Age affect the BAAS URL?
(Disclaimer: I have not tried to do it myself, but this is a suggestion.) < / P>
API BAS currently sets the path segment for a certified user's UID when the $ user is used. For example, if you sent a request with a valid login token for a user with UUID bd397ea1-a71c-3249-8a4c-62fd53c78ce7, then path / user / $ {user} / users / bd397ea1-a71c-3249 - 8a4c-62fd53c78ce7, only allow that user unit.
In this way, through your application, you can set permissions for each user, and every object, as objects are created with your application, assuming you have authenticated the user, Undoubtedly.
Ref:
Comments
Post a Comment