API access token scope restrictions (1.7.0)
A security improvement to the creation of access tokens for privileged authentication through the Resources API.
- Changed
POST /resources/access_tokenso that thescopeof a new token is restricted to the chain given in theX-Spaaza-Chain-IDheader of the request: onlychain:{chain_id}andread_businesses:{chain_id}for that chain are accepted. A request whosescopenames a different chain, or uses any other scope key, is rejected withaccess_denied(code 424) and no token is created. Previously the submittedscopewas stored unchanged. Existing tokens are not affected. See scope.