ArchitectureSecurity model
Endpoints with no authentication
Each API request needs a session or a token. A few endpoints that show nothing secret need none.
A request to /api/v1 with no session and no token gets the answer 401.
1 / 3
Authentication is the rule. The endpoints in these two tables are the exceptions.
Open because they show nothing secret
| Endpoint | Note |
|---|---|
/healthz | Tells that the server is alive. |
/api/openapi.json | The OpenAPI document. |
/api/docs | Swagger UI. It asks for an API token to send requests. |
| The static files of the dashboard | The dashboard asks you to sign in before it shows data. |
Open because the caller has no proof yet
| Endpoint | Who calls it |
|---|---|
/api/v1/auth: status, setup, login, logout | A browser, before it signs in |
/api/v1/auth: the two calls of ferry login | A terminal, to start a login and to get its token |
Webhooks do not use the account or an API token. See Deploy hook keys and GitHub webhooks.
The proxy answers one path with no authentication. See The domain check path.
ferryd sends no CORS headers, and its pages have protective headers. See Changes come from the dashboard only.