Auth of an API user¶
Every non-public API needs the token of an API user : the application calling. It is the first of the two gates.
| Header | x-am-authorization: <token> |
| Get it | POST /api/system-api/<user path>/token with { "u", "p", "expiresInSeconds"? } |
| Answer | { "token", "refresh_token", "expires_in" } |
| In code | g.req.auth.authAMUser : the API user, with its name and groups. |
expiresInSecondsis optional :jwtOptions.expiresInof the configuration otherwise, 72 hours by default. Refresh with{ "refresh_token" }while the refresh token is valid (refreshTokenValidForSafter the token expired, 900 seconds by default).- The groups of the API user decide which APIs, tables and fields the application reaches. A person token, when the API asks for one, narrows it further.