Hide Authorization Token from Request Headers in browser for headless magento 2Magento 2: How can I Revoke an Authorization TokenRest API strategy for mobile app in Magento 2Adding extension attributes to Order API EndpointMagento 2: How to check if Authorization Token is validNeither Token nor Oauth API Authentication are working Magento 2.2.3Magento 2 rest API - How to Manage API Authentication Lifecycle on Mobile Devices Application?Unable to get access_token for Magento2.0HTTP 401 Basic Authorization error accessing Magento 2 Rest APIFirst steps of creating API integration with Magento2.3Calling M2 REST API from browser for anonymous users
Printing a list as "a, b, c." using Python
Are sweatpants frowned upon on flights?
Can a network vulnerability be exploited locally?
Can I lend a small amount of my own money to a bank at the federal funds rate?
Is this position a forced win for Black after move 14?
Why did Lucius make a deal out of Buckbeak hurting Draco but not about Draco being turned into a ferret?
Stolen MacBook should I worry about my data?
What ways are there to "PEEK" memory sections in (different) BASIC(s)
Can someone identify this unusual plane at airport?
If I said I had $100 when asked, but I actually had $200, would I be lying by omission?
What does GDPR mean to myself regarding my own data?
Why nature prefers simultaneous events?
Is allowing Barbarian features to work with Dex-based attacks imbalancing?
Is the Amazon rainforest the "world's lungs"?
Employing a contractor proving difficult
How does attacking during a conversation affect initiative?
Should I ask for a raise one month before the end of an internship?
Cutting numbers into a specific decimals
Is there an in-universe explanation given to the senior Imperial Navy Officers as to why Darth Vader serves Emperor Palpatine?
Would it be better to write a trilogy over a much longer series?
How do you say "half the time …, the other half …" in German?
Fantasy Macro Economics: What would Merfolk trade for?
Is it unusual for a math department not to have a mail/web server?
Another "Ask One Question" Question
Hide Authorization Token from Request Headers in browser for headless magento 2
Magento 2: How can I Revoke an Authorization TokenRest API strategy for mobile app in Magento 2Adding extension attributes to Order API EndpointMagento 2: How to check if Authorization Token is validNeither Token nor Oauth API Authentication are working Magento 2.2.3Magento 2 rest API - How to Manage API Authentication Lifecycle on Mobile Devices Application?Unable to get access_token for Magento2.0HTTP 401 Basic Authorization error accessing Magento 2 Rest APIFirst steps of creating API integration with Magento2.3Calling M2 REST API from browser for anonymous users
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;
We are using reactJS as frontend for magento 2 website using magento 2 rest APIs. But the authorization token is visible in the browser dev tools posing security risk.
Kindly suggest a way to hide authorization token from browser.
Also we want to block API hits from any other tool (e.g. postman,arc etc.) and allow API hits only through reactJS end.
magento2 rest-api nginx react
add a comment |
We are using reactJS as frontend for magento 2 website using magento 2 rest APIs. But the authorization token is visible in the browser dev tools posing security risk.
Kindly suggest a way to hide authorization token from browser.
Also we want to block API hits from any other tool (e.g. postman,arc etc.) and allow API hits only through reactJS end.
magento2 rest-api nginx react
add a comment |
We are using reactJS as frontend for magento 2 website using magento 2 rest APIs. But the authorization token is visible in the browser dev tools posing security risk.
Kindly suggest a way to hide authorization token from browser.
Also we want to block API hits from any other tool (e.g. postman,arc etc.) and allow API hits only through reactJS end.
magento2 rest-api nginx react
We are using reactJS as frontend for magento 2 website using magento 2 rest APIs. But the authorization token is visible in the browser dev tools posing security risk.
Kindly suggest a way to hide authorization token from browser.
Also we want to block API hits from any other tool (e.g. postman,arc etc.) and allow API hits only through reactJS end.
magento2 rest-api nginx react
magento2 rest-api nginx react
edited Aug 17 at 9:02
Lokesh Naik
asked Aug 16 at 12:54
Lokesh NaikLokesh Naik
663 bronze badges
663 bronze badges
add a comment |
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "479"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fmagento.stackexchange.com%2fquestions%2f285634%2fhide-authorization-token-from-request-headers-in-browser-for-headless-magento-2%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Magento Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fmagento.stackexchange.com%2fquestions%2f285634%2fhide-authorization-token-from-request-headers-in-browser-for-headless-magento-2%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown