In workflows that use mostly site visitor, site member, or Wix user authentication, you may occasionally need to make calls with elevated permissions. You can use the JavaScript SDK to provide specific calls with Wix app authentication.
The process involves two steps:
Important: Exposed elevated function calls create a security risk for privilege escalation attacks. Make sure to protect your exposed function calls with the appropriate logic.
To elevate permissions for API calls:
The first step is to set up your app's backend to handle requests for elevated function calls from your frontend.
To set up your backend:
createClient
and AppStrategy
from the Wix SDK module.
Note: You can use your preferred method to expose HTTP functions from your self-hosted backend. For this example, we used the express NPM package.
authorization
header from incoming requests. When you send requests to the endpoint from your frontend code, this header's value will be an access token that includes authentication data for the site visitor or member.
createClient()
to create a client that can make authenticated SDK calls. Use AppStrategy
to construct the auth
value for your createClient()
call. Chain a call to elevated()
to your call to the AppStrategy
constructor. Your createClient()
call should include your app ID, app secret key, access token, and SDK module. You can find your app ID and app secret key in your app's dashboard.
createClient()
returns a client that can make API calls with Wix app authentication. To make calls with site visitor or site member authentication, create a second client without using elevated()
.
Next, send authenticated requests from your site's frontend code to your backend endpoint.
To send requests:
createClient()
as well as the relevant host module.
auth()
and host()
functions from the appropriate host module.
fetchWithAuth
function to make calls to your app's backend endpoint. This function automatically signs API calls with an authorization header that identifies the current site visitor or member.