[v11.2.x] area/configuration: adds docs for actions_allow_post_url security option (#94128)
area/configuration: adds docs for actions_allow_post_url security option (#93629)
adds docs for actions_allow_post_url security option
(cherry picked from commit 5c9486afbc)
Co-authored-by: Brian Gann <briangann@users.noreply.github.com>
This commit is contained in:
co-authored by
Brian Gann
parent
c7307f997d
commit
35b3075d06
@@ -701,6 +701,18 @@ You can enable both policies simultaneously.
|
||||
|
||||
Set the policy template that will be used when adding the `Content-Security-Policy-Report-Only` header to your requests. `$NONCE` in the template includes a random nonce.
|
||||
|
||||
### actions_allow_post_url
|
||||
|
||||
Sets API paths to be accessible between plugins using the POST verb. This is a comma separated list, and uses glob matching.
|
||||
|
||||
This will allow access to all plugins that have a backend:
|
||||
|
||||
`actions_allow_post_url=/api/plugins/*`
|
||||
|
||||
This will limit access to the backend of a single plugin:
|
||||
|
||||
`actions_allow_post_url=/api/plugins/grafana-special-app`
|
||||
|
||||
<hr />
|
||||
|
||||
### angular_support_enabled
|
||||
|
||||
Reference in New Issue
Block a user