Skip to content

docs(15.9): api.access.token.required was removed - #557

Merged
marevol merged 1 commit into
mainfrom
docs/remove-api-access-token-required
Sep 25, 2026
Merged

marevol merged 1 commit into
mainfrom
docs/remove-api-access-token-required

Conversation

@marevol

@marevol marevol commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Summary

Document the removal of api.access.token.required in Fess 15.9.

The setting refused API requests from users who were not logged in. In 15.9 the default search UI is a static theme that searches through /api/v2/search, so the setting only left anonymous users with an empty search page, and it was removed from Fess.

Changes

  • */15.9/config/properties.rst: regenerated with tools/update_properties_doc.sh; the api.access.token.required row is gone.
  • */15.9/config/properties.po: the key's description is dropped from the catalogues.
  • */15.9/install/upgrade.rst (7 languages): new section "api.access.token.required Was Removed" in the 15.8 to 15.9 part. It says that a value left under the key has no effect, that anonymous API requests are now answered with the guest roles, that login.required=true keeps anonymous users from searching, and that access tokens still add their permissions (an unregistered or expired token is still refused).

Only the rows for this key were taken from the regeneration; other differences between the generated pages and the current fess_config.properties are left for a separate update.

Checks

  • python3 tools/gen_properties_doc.py --check: the 7 properties pages agree
  • python3 tools/check_headings.py */15.9/install/upgrade.rst: no mismatches
  • docutils parse of the seven upgrade.rst files: no new errors or warnings

Dependency

This describes codelibs/fess#3496, which removes api.access.token.required. Merge it together with, or after, that PR.

Fess 15.9 no longer has api.access.token.required. Regenerate the 15.9
properties pages and drop the key's description from the translation
catalogues, and add a section to the 15.9 upgrade notes in all seven
languages: a value left under the key has no effect, anonymous API
requests are now answered with the guest roles, login.required=true is
the way to keep anonymous users from searching, and access tokens work
as before.
@marevol marevol self-assigned this Sep 25, 2026
@marevol
marevol merged commit 0d73589 into main Sep 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant