[v11.2.x] area/configuration: adds docs for actions_allow_post_url security option (#94128)

area/configuration: adds docs for actions_allow_post_url security option (#93629)

adds docs for actions_allow_post_url security option

(cherry picked from commit 5c9486afbc)

Co-authored-by: Brian Gann <briangann@users.noreply.github.com>
This commit is contained in:
grafana-delivery-bot[bot]
2024-10-01 22:59:43 -04:00
committed by GitHub
co-authored by Brian Gann
parent c7307f997d
commit 35b3075d06
@@ -701,6 +701,18 @@ You can enable both policies simultaneously.
Set the policy template that will be used when adding the `Content-Security-Policy-Report-Only` header to your requests. `$NONCE` in the template includes a random nonce.
### actions_allow_post_url
Sets API paths to be accessible between plugins using the POST verb. This is a comma separated list, and uses glob matching.
This will allow access to all plugins that have a backend:
`actions_allow_post_url=/api/plugins/*`
This will limit access to the backend of a single plugin:
`actions_allow_post_url=/api/plugins/grafana-special-app`
<hr />
### angular_support_enabled