Skip to main content

API access token scope restrictions (1.7.0)

Sam Critchley
Co-Founder

A security improvement to the creation of access tokens for privileged authentication through the Resources API.

  • Changed POST /resources/access_token so that the scope of a new token is restricted to the chain given in the X-Spaaza-Chain-ID header of the request: only chain:{chain_id} and read_businesses:{chain_id} for that chain are accepted. A request whose scope names a different chain, or uses any other scope key, is rejected with access_denied (code 424) and no token is created. Previously the submitted scope was stored unchanged. Existing tokens are not affected. See scope.