From 35b3075d063573541d6ba6d757b429b20ecc28b5 Mon Sep 17 00:00:00 2001 From: "grafana-delivery-bot[bot]" <132647405+grafana-delivery-bot[bot]@users.noreply.github.com> Date: Tue, 1 Oct 2024 22:59:43 -0400 Subject: [PATCH] [v11.2.x] area/configuration: adds docs for actions_allow_post_url security option (#94128) area/configuration: adds docs for actions_allow_post_url security option (#93629) adds docs for actions_allow_post_url security option (cherry picked from commit 5c9486afbc6081fcb7ac5287161e96dc2ad7300d) Co-authored-by: Brian Gann --- .../setup-grafana/configure-grafana/_index.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/docs/sources/setup-grafana/configure-grafana/_index.md b/docs/sources/setup-grafana/configure-grafana/_index.md index 4e0fd9e5697..ea55d67d5db 100644 --- a/docs/sources/setup-grafana/configure-grafana/_index.md +++ b/docs/sources/setup-grafana/configure-grafana/_index.md @@ -701,6 +701,18 @@ You can enable both policies simultaneously. Set the policy template that will be used when adding the `Content-Security-Policy-Report-Only` header to your requests. `$NONCE` in the template includes a random nonce. +### actions_allow_post_url + +Sets API paths to be accessible between plugins using the POST verb. This is a comma separated list, and uses glob matching. + +This will allow access to all plugins that have a backend: + +`actions_allow_post_url=/api/plugins/*` + +This will limit access to the backend of a single plugin: + +`actions_allow_post_url=/api/plugins/grafana-special-app` +
### angular_support_enabled