Skip to content

Conversation

@JiahuiWho
Copy link
Contributor

  • Update reCAPTCHA config and disabling warning
  • Add rate limit section
  • Add role based permission section

@stellar-jenkins
Copy link

Copy link
Contributor

@marwen-abid marwen-abid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Nice work explaining the ReCaptcha / MFA configs.


### Role-Based Permissions and Authentication

All authenticated API routes require clients to present either an SDP-issued API key or a JWT derived from the SEP10/SEP24 flows. After authentication, the platform enforces fine-grained authorization through role-based permissions. The primary roles are:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we may want to specify that the roles described below are specific to the JWT token auth.
API Keys offer more fine grained permissions for read/write.

Image

@stellar-jenkins
Copy link

1 similar comment
@stellar-jenkins
Copy link

@JiahuiWho JiahuiWho merged commit 5b67e18 into docpoc-sdp-main Nov 24, 2025
3 checks passed
@JiahuiWho JiahuiWho deleted the docpoc-sdp-security branch November 24, 2025 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants