Netbox API token scope enforcement for IP address creation in test environment
25.5K reputation · 24 Feb 2025, 07:09 UTC
Netbox API token‑based authentication
The goal is to confirm that an API token created with only the 'read' scope blocks write‑like operations such as creating a new IP address through the /api/ipam/ip-addresses/ endpoint when testing an integration without production credentials.
However, anecdotal reports suggest that certain endpoints may still permit implicit creation of related objects (e.g., temporary IP allocations) even when the token lacks write permissions, because the permission check is bypassed for objects already present in the request payload.
This uncertainty raises questions about the reliability of scope‑based restrictions in a test environment and whether additional constraints are needed to prevent unintended state changes.
- Does the IPAM endpoint enforce the read scope for POST requests that include a new address?
- Are temporary allocations or cached objects subject to the same scope restrictions?
- What additional token scopes or endpoint‑specific permissions are required to reliably block unintended state changes in a test environment?