You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, it's the frontend that checks the moderator status but the API is open…
Expected behavior
The API should be given the openfoodfacts, cookie, check that the user is a moderator and give a token to continue the work.
(refer to folksonomy engine which is doing it)
The tokens should have a reasonable expiry and can be stored in the table.
Note by Pierre: ticket creation API should of course be public
The text was updated successfully, but these errors were encountered:
teolemon
changed the title
API access should be closed to only moderators
Ticket listing and resolution API access should be closed to only moderators
Nov 7, 2024
What
Currently, it's the frontend that checks the moderator status but the API is open…
Expected behavior
The API should be given the openfoodfacts, cookie, check that the user is a moderator and give a token to continue the work.
(refer to folksonomy engine which is doing it)
The tokens should have a reasonable expiry and can be stored in the table.
Note by Pierre: ticket creation API should of course be public
The text was updated successfully, but these errors were encountered: