# Confusion about API Authenticated User

**URL:** <https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [May 30, 2024, 11:37pm UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042 "2024-05-30T23:37:43Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![BrainFried](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/brainfried/32/388499_2.png) [@BrainFried](https://meta.discourse.org/u/BrainFried)\
**Post date:** [May 30, 2024, 11:37pm UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042/1 "2024-05-30T23:37:43Z")

</div>

I have a question more about the security of using the API because I think I’m missing some trivial concept with my lack of experience.

I have a headless implementation of discourse to integrate into my frontend and I’ve successfully enabled sso for user authentication.

My initial understanding was that I was using SSO to authenticate as the “activeUser” to fetch activeUser-specific data from the api. I see now, that’s not entirely correct.

I see now that the data that is returned seems to be dependent on the ‘api-username’ passed into the header. But I’m using an Admin API key so I believe this means that I can fetch any user’s data that I want by passing the correct username for “api-username”.

So my question boils down to, It’s seems like the API doesn’t introduce a concept of “activeuser” and I have to adjust the active user by retrieving the username by external\_id then using that as the api-username throughout the active session, is that correct?

If my understanding is correct, isn’t this easy for a hacker to just modify the api-username in the header to retrieve chat discussions for any user?

Any additional information will be appreciated to help me understand. Thanks!

Some related articles that I’ve read:

> [@User API keys specification](https://meta.discourse.org/t/user-api-keys-specification/48536):
>
> Discourse contains a system for generating API keys per user if a very specific protocol is followed. This feature facilitates “application” access to Discourse instances without needing to involve moderators. High level description At a high level: Client (desktop app, browser plugin, mobile app) generates a private/public key pair and return url Client redirects to a route on discourse giving discourse its public key Discourse gets approval from user to use app Discourse generat…

> [@Get notifications via the API](https://meta.discourse.org/t/get-notifications-via-the-api/120951):
>
> If you have an existing website or application and you would like to encourage discussion on your Discourse forum it can be helpful to display Discourse notifications inside of your application. This guide will show you how to use the Discourse API to fetch notifications for a user and how to mark them as read. The recommended way of using the API is to have your application make back-end requests to Discourse and then pass that data to the front-end/presentation layer of your application. Che…

> [@Using Discourse API to return user data when the "Require authentication to read content on this site, disallow anonymous access." setting is checked](https://meta.discourse.org/t/using-discourse-api-to-return-user-data-when-the-require-authentication-to-read-content-on-this-site-disallow-anonymous-access-setting-is-checked/28404):
>
> Hi, I enabled the setting “Require authentication to read content on this site, disallow anonymous access”. I’m making a GET request to the /users/by-external/{EXTERNAL\_ID}.json endpoint, and without the above setting enabled, it returns a user perfectly fine. But when I enable the above setting, the GET request returns nothing. For reference, I have SSO enabled. Let me know if there’s a workaround or if I’m thinking about this incorrectly. Thanks in advance!

> [@Per User API Keys Not Working](https://meta.discourse.org/t/per-user-api-keys-not-working/201415):
>
> I’m following the guidance for getting per user api keys: [User API keys specification](https://meta.discourse.org/t/user-api-keys-specification/48536). I’ve gone through the steps: client generates a public/private key pair and return url, goes to a discourse route, user gives approval to discourse to use the app, and discourse generates an api key. But when discourse sends back the API key as a “payload” in the return url, that key doesn’t work. I try to decrypt it, but I can’t. I plug that key into some standard javascript decryption (like in the answer [h…](https://stackoverflow.com/questions/8750780/encrypting-data-with-a-public-key-in-node-js)

---

_[View the full topic](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042)._
