enonic / lib-guillotine

Apache License 2.0
3 stars 0 forks source link

Conclude strategies for protecting access to Guillotine API #223

Open sigdestad opened 2 years ago

sigdestad commented 2 years ago

By default, Guillotine API is accessible for anyone, which is probably fine. However, in some cases - like when accessing draft items (previewing) one needs to protect the API from public access. Also, for intranets one may need to support a closer integration i.e. if content items have permissions (not read for everyone).

Possible solutions:

Topic needs to be discussed before moving forward