Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

JSON:API Permission Access provides an additional permission on JSON:API based routes. Without this permission, users (other than administrators) will be unable to retrieve data from these endpoints. This can be useful when pairing with Consumers and Simple OAuth as you need to attach scope(s) to specific role(s), which can have very specific permissions...like this one 🙂

Features

When you enable JSON:API there is no straightforward way to provide access controls on various routes. This can potentially lead to exposing some data that you do not want to expose, i.e. /jsonapi/user/user.

From the JSON:API module security considerations documentation, we can see that:

  • Entity Access is respected.
  • Field Access is respected.
  • When modifying data, validation constraints are respected.
  • The internal flag is respected (see documentation about how it can be set on an entity type definition, field definition or property definition).

Adjusting the permissions on entities/fields for specific roles can be cumbersome so this aims to provide a simple layer on top of all that for easy control.

Post-Installation

After installation, any user who attempts to visit JSON:API based routes will be met with an access denied if they do not have the specified permission.

You can add the permission to any role you would like to allow access from the /admin/people/permissions page.

Additional Requirements

None.

  • Simple OAuth: This module defines scopes which are attached to specific roles. This permission can be assigned to a specific role, which can then be used as part of a scope for OAuth based access flows.

Similar projects

  • Drupal REST & JSON API Authentication: This module provides Basic authentication (based on Drupal users) out of the box as well as API Key authentication, but places more advanced features such as OAuth behind a paywall. With JSON:API Permission Access + Simple Oauth + Consumers this can be accomplished at no cost.
  • Jsonapi Role Access: This module does a very similar implementation except it introduces added complexity with separate configuration when this can be achieved through the standard permission handling methods.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
3
Tracked since
Feb 2024
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Release Timeline

Releases

Version Type Core Release date
1.0.1 Stable Apr 21, 2024
1.0.0 Stable Feb 9, 2024
1.0.x-dev Dev Feb 9, 2024