Table of Contents

Authentication and authorization

Products: FastReport Cloud, FastReport Corporate Server, FastReport Publisher

The process of user data authentication and granting user certain rights in Service solutions is carried out in one of two available ways:

  1. Via JWT token.

    In this case, authentication must be done manually, and the token will only be valid for 5 minutes, during which time the user must log in to their application. When connecting to the server, the browser will redirect to the authentication server and then generate an access token. We restrict the possibility of retrieving the JWT token to the user personally from a security point of view.

    If the user has not logged in to the application within 5 minutes, the authentication must be re-authenticated. If the user has logged in, re-authentication is not required.

  2. Via API key.

    In this case, the obtaining of access rights is performed for server applications. To get an API key, a user must be present. However, the key itself can be valid for a long time, for example, a year.

Retrieve the first API key

To get the first API key, access the user panel. If for some reason you do not have access to the user panel, you can request a key as described below.

The easiest way to retrieve a key is to open the Api keys tab and create one on this page.

Option 2:

  1. Open the link in your browser: <{host_name}/account/signin?r={host_name}/api/manage/v1/ApiKeys>.

    If you click on this link, it will direct you to the automatic browser authentication process.

  2. Now when authentication has passed, you need to request a new key.

    Press F12 or Ctrl+Shift+I to open the developer panel. The key combinations may differ from the default, in that case open the developer panel via the browser menu

  3. Copy and run the code in the JavaScript console.

    This code will make a POST request to the URL {host_name}/api/manage/v1/ApiKeys to create a new access key valid till 2030.

    await fetch('{host_name}/api/manage/v1/ApiKeys', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json;charset=utf-8'
      },
      body: JSON.    stringify({
        "description": "Generated by js develop panel",
        "expired": "2030-01-01T07:41:23.399Z"
      })
    });
    
  4. Refresh the browser page and get the result.

    {
        "apiKeys": [
            {
                "value": "cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey",
                "description": "Generated by js develop panel",
                "expired": "2030-01-01T07:41:23.399Z"
            }
        ],
        "count": 1
    }
    

Now you can use the API key. In the example above, cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey was used.

There is no need to retrieve a new API key through the browser again.

How to use API key

The key should be passed with each request in the Authorization: Basic. You should use apikey as the username and the key value as the password. For example:

Authorization: Basic Base64Encode(apikey:cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey);

Where Base64Encode is a function to encode a string into base64.

For FastReport.Cloud.SDK there is a special class that allows you to add a key to the request header FastReportCloudApiKeyHeader.

To add the necessary header, create a new HttpClient.

HttpClient httpClient = new HttpClient();
httpClient.BaseAddress = new Uri({host_name});
httpClient.DefaultRequestHeaders.Authorization = new FastReportCloudApiKeyHeader(apiKey);

Now this HttpClient can be used for all requests.

Hosting under a base path? If the report server is served under a prefix (e.g. https://company.com/reports), set BaseAddress with the prefix and a trailing slash — new Uri("https://company.com/reports/"). Without the trailing slash, .NET resolves the relative API paths (api/...) against the host root and silently drops the /reports prefix, so every request 404s. See section 8 of Deploying under a custom base path.

Retrieve new API key

To retrieve a new key, call the following method CreateApiKeyAsync(CreateApiKeyVM, CancellationToken)

CreateApiKeyVM model = new CreateApiKeyVM()
{
    Description = "Created by FastReport.Cloud.SDK",
    Expired = DateTime.UtcNow.AddYears(1)
};

IApiKeysClient apiKeysClient = new ApiKeysClient(httpClient);
await apiKeysClient.CreateApiKeyAsync(model);

Whenever possible, use asynchronous method analogs instead of synchronous methods.

This function will result in a ApiKeyVM model.

What next?