Idea

cool-daniel avatar image
cool-daniel suggested

Secret key permission management

It would be usefull if you could set permissions for each secret key to limit its usage on specific categories like Player Data Management or Account management within the admin or server api while denying access to other categories of the api. This would enable admins to give out secret keys without exposing all functionality (like for example only letting a secret key call the GetPlayerProfile while not working for BanUsers)

apisAccount Management
2 comments
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

larissa avatar image larissa commented ·

Agreed! :)

One addition to this: It would also be useful, to be able to limit it to executing certain cloudscript handlers

1 Like 1 ·
Brent Batas (Lisk) avatar image Brent Batas (Lisk) commented ·

Agreed, this is a good idea.

0 Likes 0 ·

1 Comment

·
david-marcelis avatar image
david-marcelis commented

Want to upvote this issue. The idea of having the Server Key have access to the Admin API is scary. This means if a server or matchmaker was compromised, it gives permissions to change builds or worse.

Just a separation between Server Key, Matchmaker Key, and Admin Key would already greatly reduce the potential impact.

10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Write a Comment

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Your Opinion Counts

Share your great idea, or help out by voting for other people's ideas.