xmidt-org/webpa-common

Take client ID from header for cases when authentication method user wasn't through JWTs

joe94 opened this issue · 0 comments

joe94 commented

Currently the owner of a webhook comes from a SAT token. If the authentication method is not SAT, we should check for the header X-Xmidt-Client-id