Forum Discussion

Alberto_Flores's avatar
Alberto_Flores
Icon for Nimbostratus rankNimbostratus
Sep 09, 2021
Solved

Operator Role for user with only API permission

Hello.

 

My question is : Is it possible to create an user and granted Operator Role but ONLY allow it to use API calls ?

 

We would like to denied the access to the web interface but without blocking web resources through API for the Operator role.

 

Thanks in advance.

  • From what I read and from all my testing, the answer appears to be "no".

     

    See https://devcentral.f5.com/s/articles/icontrol-rest-fine-grained-role-based-access-control-30773

     

    "The role is important. When the access privileges conflict between the role and the fine grained RBAC, the stricter authorization is chosen. For example, if the RBAC is configured to allow PATCH or POST but the user's role is guest (no alteration allowed), the user won't be able to perform these methods."

     

     

    To be honest, I'm very confused about this, because it seems to make the entire concept of fine-grained API access more or less pointless. If the API user can still be used to log in interactively with full access rights according to the user role, why would I even bother to define more granular API rights?

    But maybe I'm just missing something. Happy to hear any counterpoints.

1 Reply

  • From what I read and from all my testing, the answer appears to be "no".

     

    See https://devcentral.f5.com/s/articles/icontrol-rest-fine-grained-role-based-access-control-30773

     

    "The role is important. When the access privileges conflict between the role and the fine grained RBAC, the stricter authorization is chosen. For example, if the RBAC is configured to allow PATCH or POST but the user's role is guest (no alteration allowed), the user won't be able to perform these methods."

     

     

    To be honest, I'm very confused about this, because it seems to make the entire concept of fine-grained API access more or less pointless. If the API user can still be used to log in interactively with full access rights according to the user role, why would I even bother to define more granular API rights?

    But maybe I'm just missing something. Happy to hear any counterpoints.