Skip to content

Security Restrict — Reference

Reference · Advanced · Server Connect

Require an authenticated provider identity and, optionally, named permissions.

Require an authenticated provider identity and, optionally, named permissions.

  • A configured Security Provider and a disposable test account for verifying authentication behavior.

Require an authenticated provider identity and, optionally, named permissions.

Setting Meaning and example
ProviderThe provider used to check the request. Place Restrict before the private data access or mutation.
PermissionsNamed permissions configured in the provider. The supplied set must be satisfied; these are not arbitrary role names that become valid merely by typing them here.
Login URLOptional destination for an unauthenticated browser navigation. With no login destination, the provider returns unauthorized behavior, commonly HTTP 401.
Forbidden URLOptional destination when an authenticated user lacks required permissions. With no destination, the provider returns forbidden behavior, commonly HTTP 403.

Protect a test data action with Restrict before its query. Test three sessions: logged out, logged in without the permission, and logged in with it. Only the permitted session should receive the private data. Separately restrict the query to records that identity may access.

An AJAX request receiving a redirect does not automatically navigate the top-level page. Node.js uses a special 222 response for fragment navigation; PHP adds a redirect query parameter to a login redirect. Do not build cross-runtime client logic around an assumed identical redirect shape. Login status alone does not provide record-level authorization.

Use the security and login guides for the surrounding provider, form, session and server-access configuration.

You can configure the documented fields and distinguish a successful result from the failure or limitation described here.