Skip to content

Add ability to restrict API tokens by IP address #17773

Open
@di

Description

@di

The npm repository has the notion of an access/API token that can be optionally restricted by IP address ranges:

Image

We could add a similar option, include it as a caveat on the token, and compare it with remote_addr when authenticating.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions