SOAP access for non-primary-admin
Hi there,
I was wondering if SOAP access was going to be made available for non-primary-admin accounts?
I was discussing this feature with my software team to 'get' user data (not setting any data) , but due to least-priviledge concerns, I can't allow them access to admin level accounts.
Thanks!
Jason
-
Official comment
Hi Jason,
Thank you for reaching out.
At the moment, Cerberus only supports primary admin access through SOAP.
Multi-level and reduced-privileged access level through SOAP is under evaluation.
We would love to hear more about this specific request and its planned use; please review our feature request guidelines and provide detailed information on the functionality you are looking for. We ask that you be as detailed as possible to help our product team understand what you need.
Ron
Product Team
-
Adding comment on behalf of Jason.
What is the problem that this feature would fix?
Currently, SOAP access requires the admin account.
Why is it a problem?
We would like our application to be able to get data from Cerberus without requiring the admin account.
Is there a workaround you currently have for this problem?
I have written a Powershell script to output the data into a CSV. This then is imported into our app.
The problem with this is that it is not real-time.
Do you have a suggestion on how you would like to see the problem fixed?
It would be better if a non-admin account could access SOAP API data, even if it is read-only 'GET' access.
How big is the problem? Who is affected by this problem (End Users, Admins, etc.)?
As it stands, the data could be out-of-date if there were any changes since the data was extracted.
The process also requires more steps and introduce additional potential points of failure.
Thanks for your consideration!
-Jason
0 -
Is there a place that we an upvote this request? I have an immediate need for this. I need others to setup users so we wrote an application for them to so. The User control via the web admin gives them to much control. The Cerberus Web admin face for User access allows someone to change groups, policies, etc.
0 -
Hello Jason,
If you hit the little arrow up to the right of the post, that will upvote the request. Upvoting helps let us know what features our community are looking forward to the most, or want to have said functionality.
0 -
Has there been any update to this feature request? I see from Ron's post a couple years ago that this was under evaluation.
This feature request is important to us as well. I am including responses to questions in the feature request guidelines below.What is the problem that this feature would fix?
The SOAP API is currently only available to the primary administrator account. Therefore, we cannot make the API available for general use by any standard user.
Why is it a problem?
We have the need for certain non-administrative users to programmatically perform specific functions, such as creating public shares. There is no way for us to grant this ability without exposing all API operations. These users should not be able to use the API to create/delete users or manage other users’ directories.
Is there a workaround you currently have for this problem?
No, there is no workaround.
Do you have a suggestion on how you would like to see the problem fixed?
It should be possible for a non-administrative user to access the SOAP API and perform only operations that they have access to perform through the web interface. E.g. a user should be able to call the SOAP API to create a public share on their files/folders, but not any other user’s files/folders. They should not be able to create/delete users via the API (unless they have access to do so through the web interface)
How big is the problem? Who is affected by this problem (End Users, Admins, etc.)?
This is a significant problem for us. We have internal teams that would like to programmatically generate share links for external users to upload large files. This would allow us to better integrate Cerberus SFTP with other services that we use.
2 -
Hello Bill,
Unfortunately our Product team has decided to not move forward with this enhancement at this time. They did mention it would be looked into for future considerations. I apologize that this may not be the news you wanted, but I did note some differences between your request;
This request was more centered around other admins to be able to access SOAP and complete administrative tasks, while it seems your request may be more aimed at allowing end users/non admin users to make API calls. If you'd like to submit this in it's own enhancement request, I can get that to our Product team for their review.
0 -
Hi Connor,
Thanks for the quick response. I submitted this as a separate feature request per your suggestion.
API Access for non-admin accounts – Cerberus Support (cerberusftp.com)
0
Please sign in to leave a comment.
Comments
7 comments