-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[#416] Myapps endpoint toggle password. #434
[#416] Myapps endpoint toggle password. #434
Conversation
…16-myapps-endpoint-toggle-password
@arlina-espinoza @arshad do we have some code that would check user permission in teams ? I would like to add some routine that would make sure users cannot pull credentials for different developers or teams. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@arlina-espinoza @arshad do we have some code that would check user permission in teams ? I would like to add some routine that would make sure users cannot pull credentials for different developers or teams.
@minnur If you switch the paths to something like /user/{user}/apps/{app}/api-keys
and /teams/{team}/apps/{app}/api-keys
, you could take advantage of the route requirement _app_access_check_by_app_name
: view
to enforce a view access permission. See DeveloperAppRouteProvider::getCanonicalRouteByDeveloper()
<?php | ||
|
||
/** | ||
* Copyright 2018 Google Inc. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
* Copyright 2018 Google Inc. | |
* Copyright 2020 Google Inc. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks Arlina, I am working on this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Resolved in b4cd0f2
…16-myapps-endpoint-toggle-password
All (the pull request submitter and all commit authors) CLAs are signed, but one or more commits were authored or co-authored by someone other than the pull request submitter. We need to confirm that all authors are ok with their commits being contributed to this project. Please have them confirm that by leaving a comment that contains only Note to project maintainer: There may be cases where the author cannot leave a comment, or the comment is not properly detected as consent. In those cases, you can manually confirm consent of the commit author(s), and set the ℹ️ Googlers: Go here for more info. |
@googlebot I consent. |
CLAs look good, thanks! ℹ️ Googlers: Go here for more info. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @minnur , I tested locally and fixed the tests. LGTM 👍
Related to #415
I implemented new endpoint that returns JSON response with credentials for a given app. Credentials are getting pulled by app name and current user.