Skip to content

LDE: Expand auth beyond a static API token #1000

Description

@bjagg

Part of the LDE rollout — see #906.

The LDE endpoint currently authenticates callers with a static X-API-Key. Expand to a stronger, externally-appropriate auth model — Cognito-based — reusing the existing machinery rather than inventing new auth:

Suggested: start with a short design spike to settle the model before implementation, since the lightweight FE LDE app depends on Cognito auth being in place.

Related: #961 (tenant isolation — assigned), #989 (live cross-tenant isolation test), #990 (drop public search_path fallback), #937 (security umbrella). This is where the LDE track and the tenant-isolation follow-ups converge.

Blocks: lightweight FE LDE app.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

Status
Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions