Who may reach a route, and what a refused caller is told.
Every route requires a signed-in user unless its route data carries
:public true (BOU-568). A refusal has the shape the user module's
require-authenticated interceptor answers with, so a client sees one 401
whichever layer refused it. No Content-Type: muuntaja encodes a map body
only when none is set (ZZP-120).
Who may reach a route, and what a refused caller is told. Every route requires a signed-in user unless its route data carries `:public true` (BOU-568). A refusal has the shape the user module's `require-authenticated` interceptor answers with, so a client sees one 401 whichever layer refused it. No Content-Type: muuntaja encodes a map body only when none is set (ZZP-120).
(admin? request)Whether the signed-in user has the global admin role.
Whether the signed-in user has the global admin role.
(correlation-id request fresh)The caller's X-Correlation-ID, or fresh when it sent none.
The caller's X-Correlation-ID, or `fresh` when it sent none.
(forbidden-response message request correlation-id)403 for an API caller. A web page redirects to the login form, as it always has, so a user can sign in as someone who is allowed.
403 for an API caller. A web page redirects to the login form, as it always has, so a user can sign in as someone who is allowed.
(public? data)Whether Reitit endpoint data opts out of authentication.
Whether Reitit endpoint data opts out of authentication.
(unauthorized-response message request correlation-id)401 for an API caller; a web page sends the browser to the login form, which returns it here afterwards.
401 for an API caller; a web page sends the browser to the login form, which returns it here afterwards.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |