1
[Feature] Restrict API Key by host/ip
Source: immich-app/immich#26453 · opened by @david-thaler
I have searched the existing feature requests, both open and closed, to make sure this is not a duplicate request. • Yes The feature Incase this is a duplicate I'm apologise ahead of time, I couldn't find it myself. I believe it would be a good idea to be able to restrict an API keys usage by host/ip or even some other filters (if others can come up with any further ideas). Some tools I've found (for example tiktok remover) have resorted to suggesting the api key to be used should be just "all permissions" because of recent "permission changes". My concern with this is that obviously an api key can be used by anyone so if the key becomes compromised it's now usable by an attacker. If we are able to restrict the api key usage giving all permissions it would at least add a bit more security to this tools that don't give us the support required to fully understand the permissions needed and to avoid the trial and error hell of gues…
No pledges yet. Be the first to back this.
Comments
Similar requests
API Key api usage is not documented
1 vote · 0 comments
[Feature] Reset API keys when password is reset
1 vote · 0 comments
[Feature] Update API Key generation to be easier to read? Display as monospaced / code font?
1 vote · 0 comments
[Feature] Trusted Local Provisioning for Immich
1 vote · 0 comments
[Feature] Use OAuth2 access_token and refresh_token
11 votes · 0 comments
No comments yet.