Authentication and authorization
Products: FastReport Cloud, FastReport Corporate Server, FastReport Publisher
The process of user data authentication and granting user certain rights in Service solutions is carried out in one of two available ways:
Via JWT token.
In this case, authentication must be done manually, and the token will only be valid for 5 minutes, during which time the user must log in to their application. When connecting to the server, the browser will redirect to the authentication server and then generate an access token. We restrict the possibility of retrieving the JWT token to the user personally from a security point of view.
If the user has not logged in to the application within 5 minutes, the authentication must be re-authenticated. If the user has logged in, re-authentication is not required.
Via API key.
In this case, the obtaining of access rights is performed for server applications. To get an API key, a user must be present. However, the key itself can be valid for a long time, for example, a year.
Retrieve the first API key
To get the first API key, access the user panel. If for some reason you do not have access to the user panel, you can request a key as described below.
Open the link in your browser: <{host_name}/account/signin?r={host_name}/api/manage/v1/ApiKeys>.
If you click on this link, it will direct you to the automatic browser authentication process.
Now when authentication has passed, you need to request a new key.
Press
F12orCtrl+Shift+Ito open the developer panel. The key combinations may differ from the default, in that case open the developer panel via the browser menuCopy and run the code in the JavaScript console.
This code will make a
POSTrequest to the URL{host_name}/api/manage/v1/ApiKeysto create a new access key valid till 2030.await fetch('{host_name}/api/manage/v1/ApiKeys', { method: 'POST', headers: { 'Content-Type': 'application/json;charset=utf-8' }, body: JSON. stringify({ "description": "Generated by js develop panel", "expired": "2030-01-01T07:41:23.399Z" }) });Refresh the browser page and get the result.
{ "apiKeys": [ { "value": "cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey", "description": "Generated by js develop panel", "expired": "2030-01-01T07:41:23.399Z" } ], "count": 1 }
You can also create a key by opening the Api keys tab.
Now you can use the API key. In the example above, cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey was used.
There is no need to retrieve a new API key through the browser again.
How to use the API key
The key should be passed with each request in the header Authorization: Basic. Use apikey as the username and the key value as the password. For example:
Authorization: Basic Base64Encode(apikey:cc355oeu1z5d5wncayo33me6c1g5junqdqk4pkupid7t8ynjshey);
Where Base64Encode is a function for converting a string to base64 when using UTF8 encoding.
Retrieve new API key
To get the new key, execute the POST request to the {host_name}/api/manage/v1/ApiKeys entry point and pass JSON in the request body according to the scheme below.
{
"description": "string",
"expired": "string($date-time)"
}
Example request:
curl -X POST "{host_name}/api/manage/v1/ApiKeys" -H "accept: text/plain" -H "authorization: Basic YXBpa2V5OmNjMzU1b2V1MXo1ZDV3bmNheW8zM21lNmMxZzVqdW5xZHFrNHBrdXBpZDd0OHluanNoZXk=" -H "Content-Type: application/json-patch+json" -d "{ \"description\": \"Generated by js develop panel\", \"expired\": \"2030-01-01T07:41:23.399Z\"}"
Response scheme:
{
"value": "string",
"description": "string",
"expired": "2020-12-02T08:47:43.270Z"
}
You can also get a new key through the user panel.