From 8329a2c639ec81ee5724c205c3122024ea151b24 Mon Sep 17 00:00:00 2001 From: Peter Macdonald Date: Thu, 25 Apr 2024 15:05:12 +0200 Subject: [PATCH] removes cookie section, not needed Signed-off-by: Peter Macdonald --- docs/permissions/getting-started.md | 4 ---- 1 file changed, 4 deletions(-) diff --git a/docs/permissions/getting-started.md b/docs/permissions/getting-started.md index 7e828bac56..a33df6cfc2 100644 --- a/docs/permissions/getting-started.md +++ b/docs/permissions/getting-started.md @@ -22,10 +22,6 @@ Like many other parts of Backstage, the permissions framework relies on informat [The IdentityResolver docs](../auth/identity-resolver.md) describe the process for resolving group membership on sign in. -## Optionally add cookie-based authentication - -Asset requests initiated by the browser will not include a token in the `Authorization` header. If these requests check authorization through the permission framework, as done in plugins like TechDocs, then you'll need to set up cookie-based authentication. Refer to the ["Authenticate API requests"](https://github.com/backstage/backstage/blob/master/contrib/docs/tutorials/authenticate-api-requests.md) tutorial for a demonstration on how to implement this behavior. - ## Integrating the permission framework with your Backstage instance ### 1. Set up the permission backend