Is it possible to apply different authorization pa...
# prisma-whats-new
r
Is it possible to apply different authorization parameters/permissions based on the url? Backstory: as an admin, I want to seed my app with draft posts and then invite specific people to edit/manage/publish them by emailing them a link (without forcing them to create an account or sign in). The model I have in mind is Craigslist, where posts have secret urls that function as passwords, allowing anyone with the link to make changes. This functionality needs to live alongside normal authentication. So the same user who approved/published a post after receiving a secret url via email would need to sign in before creating a new post of their own.
n
@ryand I wonder if you can accomplish this with the anonymous auth provider we offer
r
The docs there are sparse, and I’m rather over my head. Are there any examples of how Anonymous Auth would be used?
n
it's being discussed in detail in part 3 of the Freecom tutorial series: https://www.graph.cool/freecom/
r
Thx will have a look
In the Freecom example, anonymous auth happens before messages are created, so from that point on it’s basically standard permissions: does the ID match, okay. But in my scenario, the posts are created (by an admin) before there is any user. And anyone can access the post using a secret url, not just a specific user.
What I imagine is more like a different GraphQL query for secret urls like
post/:id:/:secret
, one that applies totally separate authorization parameters than the normal
post/:id:
url
n
What if you added the post to the list of accessible posts of the user once he reaches that url?
r
I can see that working. Is the anonymous user’s client-side data overwritten if they actually create an account?
n
no you would need to handle that logic by yourself
r
Gotcha, thanks
👍 1
n
we're working on account linking support already, but right now you could initiate a script that handles the "account migration" when the user signs up