How to bloack /api calls to get content data.

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

How to bloack /api calls to get content data.

Saurabh Tripathi

Hi Everyone,

I just want to know that is there any way to restrict /api call to get content data for all content types without updating content type view permission or to restrict all /api calls coming from a domain.

I would like to block all /api call coming from a domain(example.com) but all calls from the same server (localhost:8080) would respond.

How can i achive this ? Please suggest.


For example:

If I hit the URL as (http://example.com/api/content/render/false/query/+contentType:{ContentType}/user/[hidden email]/password/admin), it should not respond with content type data

and

if hit the URL on the server as (http://localhost:8080/api/content/render/false/query/+contentType:{ContentType}/user/[hidden email]/password/admin), it should respond with content type data.

Thanks



Sent from the dotCMS Users Group mailing list archive at Nabble.com.

--
http://dotcms.com - Open Source Java Content Management
---
You received this message because you are subscribed to the Google Groups "dotCMS User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To post to this group, send email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/dotcms/1512538186949-0.post%40n5.nabble.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: How to bloack /api calls to get content data.

Xander
Hi Saurabh,

You could add an Apache/nginx in front of the dotCMS (with which you could also block by IP or something) or you could add a filter in a static plugin.

Kind regards,

Xander

--
http://dotcms.com - Open Source Java Content Management
---
You received this message because you are subscribed to the Google Groups "dotCMS User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To post to this group, send email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/dotcms/5777c8d2-347f-4cfd-9f89-debf070f1f87%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.