diff --git a/ghost/core/core/server/web/api/endpoints/admin/middleware.js b/ghost/core/core/server/web/api/endpoints/admin/middleware.js index e519535e49..f3e2d63ab8 100644 --- a/ghost/core/core/server/web/api/endpoints/admin/middleware.js +++ b/ghost/core/core/server/web/api/endpoints/admin/middleware.js @@ -14,15 +14,13 @@ const notImplemented = function (req, res, next) { return next(); } - // @NOTE: integrations have limited access for now + // @NOTE: integrations & staff tokens have limited access to the API const allowlisted = { - // @NOTE: stable site: ['GET'], posts: ['GET', 'PUT', 'DELETE', 'POST'], pages: ['GET', 'PUT', 'DELETE', 'POST'], images: ['POST'], webhooks: ['POST', 'PUT', 'DELETE'], - // @NOTE: experimental actions: ['GET'], tags: ['GET', 'PUT', 'DELETE', 'POST'], labels: ['GET', 'PUT', 'DELETE', 'POST'],