Hi there,

lets say you have a foxx-service called /update-review and you can send a 
json document( updated review) to it.

I want the service to return an error in case the user is not allowed to 
update the review.

So there must be some kind of security token send with the json document
This token then must be resolved to the userId  and the "review" document 
needs a field called "owner": $userId 
If they match the foxx-service updates the review, if they dont it sends an 
error right?

At least thats how i imagine it to be. Is there any built in solution to 
handle this?

If i implement it myself im scared of messing it up.
Also the tokens would be send over http and not https which is kind of bad 
practice isnt it?

-- 
You received this message because you are subscribed to the Google Groups 
"ArangoDB" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/arangodb/f6f7d5a7-1e13-4ea1-8a17-0942720623c4%40googlegroups.com.

Reply via email to