18F/api.data.gov

Ideas for potential admin changes

gbinal opened this issue · 1 comments

We got these ideas from an agency user, with an eye to making the information in the system more secure. They are good ideas and I'm creating this idea to put them in the backlog:

  1. Add configurable query string parameters to remove from logs. This will allow filtering of authentication related parameters with different names.
  1. Make separate roles for log viewing and analytics viewing. This will allow more users to view the analytics without having access to the API logs, which contain more detailed information about requests.
  1. Add ability to Associate API keys with an API backend, so that the API information is only available to API administrator the key is associated with. This wouldn't have to be true of all API keys, but would be an option for specific ones.

Closing as stale, on the assumption that the need will resurface if it still exists.