solidusio-contrib / solidus_paypal_marketplace

BSD 3-Clause "New" or "Revised" License
4 stars 3 forks source link

Restrict sellers API access #73

Open Jecko-o opened 3 years ago

Jecko-o commented 3 years ago

Currently data from all sellers is visible through the standard API endpoints. This is verifiable in the response from the variants controller, that includes stock items data from all the sellers, independently from who is currently logged in. Using seller dedicated API endpoints would be an easy way to restrict data viewed by seller accounts.

stale[bot] commented 3 years ago

This issue has been automatically marked as stale because it has not had recent activity. It might be closed if no further activity occurs. Thank you for your contributions.