Limit remote user domain accessibility

Discussion in 'General' started by Csedwik, May 22, 2025.

  1. Csedwik

    Csedwik New Member

    Hi,

    My client would like to connect to ISPConfig using the SOAP (remote API) interface to manage tasks such as black/whitelists, email redirects, and vacation messages.

    The challenge I'm facing is that if I create a remote user for them, they receive superadmin-level access — which means they can view and potentially modify all domains on the server, posing a security risk.

    My question is:
    Is there any way to restrict a remote user’s access to specific domains only?
    Or would I need to develop a custom middleware layer between the client system and ISPConfig to enforce such restrictions?

    Thanks in advance for your help!
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    No. Remote API operates as admin user, there are no restrictions like client or reseller level.
     

Share This Page