Friction

Feature request · Permissions & security · Blocks work

Allow whitelisted session variables via HTTP headers

1 source thread · first seen 2019-02

Summary

All custom X-Hasura headers are filtered, so switching organizations needs a new token or webhook auth; the requester asks to whitelist chosen headers as session variables.

Affects
multi-tenant app developers
Workaround
Use webhook auth or fetch a new JWT on each organization switch

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Currently all `X-Hasura-*` HTTP headers are filtered and not available to to be used in column presets or permission checks”

Report this item