Adminapp REST API Configuration
smsServiceConfig) requestAuthentication) hashFunction) hashSharedSecret) Can be used together with the 'Hash Function' to externalize session information to the client.
corsSettings) csrfProtection) If enabled, REST endpoints are protected against CSRF attacks.
With this protection, the REST API only accepts requests that contain the custom header X-Same-Domain with an arbitrary non-empty value. In cross-origin resource sharing (CORS), such requests are not considered simple requests and thus must always be preceded by a preflight request, which prevents cross-site request forgery (CSRF) attacks.
Security warning: Disabling this feature may allow CSRF attacks. Only do so if the REST client is unable to comply with the aforementioned restrictions.
usernameTransformers) linkResponseRewritingEnabled) If a 'Base URI' is configured, links are rewritten according to the configured value. Otherwise, links are rewritten according to the external view provided by the WAF (if configured an a WAF environment cookie is present).
baseUri) This property is useful in test environments where you want links contained in REST responses to be relative to the configured base URI. Note that configuring this property will take precedence over link rewriting based on the WAF environment cookie.
Example:
- Property value:
http://myhost:8090/test - The response from the REST call to
/<adminapp-uri>/rest/maintenance-messageswill contain a link tohttp://myhost:8090/test/rest/maintenance-messages.
defaultPageSize) page[limit] query parameter. Must be greater than 0 and smaller than or equal to the 'Max Page Size'. maxPageSize)
type: AdminappRest
id: AdminappRest-xxxxxx
displayName:
comment:
properties:
baseUri:
corsSettings:
csrfProtection: true
defaultPageSize: 500
hashFunction:
hashSharedSecret:
linkResponseRewritingEnabled: true
maxPageSize: 5000
requestAuthentication:
smsServiceConfig:
usernameTransformers: