Security Restrict — Reference
Require an authenticated provider identity and, optionally, named permissions.
Require an authenticated provider identity and, optionally, named permissions.
Before you begin
Section titled “Before you begin”- A configured Security Provider and a disposable test account for verifying authentication behavior.
Security Restrict
Section titled “Security Restrict”Require an authenticated provider identity and, optionally, named permissions.
Settings
Section titled “Settings”| Setting | Meaning and example |
|---|---|
| Provider | The provider used to check the request. Place Restrict before the private data access or mutation. |
| Permissions | Named permissions configured in the provider. The supplied set must be satisfied; these are not arbitrary role names that become valid merely by typing them here. |
| Login URL | Optional destination for an unauthenticated browser navigation. With no login destination, the provider returns unauthorized behavior, commonly HTTP 401. |
| Forbidden URL | Optional destination when an authenticated user lacks required permissions. With no destination, the provider returns forbidden behavior, commonly HTTP 403. |
Verification example
Section titled “Verification example”Protect a test data action with Restrict before its query. Test three sessions: logged out, logged in without the permission, and logged in with it. Only the permitted session should receive the private data. Separately restrict the query to records that identity may access.
Behavior and limits
Section titled “Behavior and limits”An AJAX request receiving a redirect does not automatically navigate the top-level page. Node.js uses a special 222 response for fragment navigation; PHP adds a redirect query parameter to a login redirect. Do not build cross-runtime client logic around an assumed identical redirect shape. Login status alone does not provide record-level authorization.
Use the complete authentication flow
Section titled “Use the complete authentication flow”Use the security and login guides for the surrounding provider, form, session and server-access configuration.
Check your result
Section titled “Check your result”You can configure the documented fields and distinguish a successful result from the failure or limitation described here.