Skip to content

User Property & Request Relationship

A custom property set belongs to an endpoint, a value for each of its properties belongs to a web user, and a request from that user to that endpoint carries the values in. The diagram follows one property set through setup and into a request.

A diagram in two halves. WebAPI Setup: a custom property set ZYX with Property A and Property B, and a web user USER1 with its X-User-Token, both feed a WebAPI endpoint ABC with property set ZYX and route POST /order; beneath it the properties for USER1 hold Value-A and Value-B. Request Execution: an HTTP request, POST /order with the X-User-Token, is matched to endpoint ABC and web user USER1, the property values from the web user are merged with the request data, and the record carries the fields Http.User.PropertyA and Http.User.PropertyB with Value-A and Value-B

Setup

  1. Create a custom property set with the properties.
  2. Create the endpoint with that set selected.
  3. Assign the web users to the endpoint, then set each user's values.

Request handling

  1. The request is matched to an endpoint by its route and method.
  2. The web user is found from the request's X-User-Token header, or from the client id inside its bearer token. The user must be enabled and assigned to the endpoint; otherwise the request has no user.
  3. The endpoint's property set names the properties, and the user's values fill them.
  4. They arrive on the WebAPI Reader's record as one Http.User.<property> field per property, beside Http.User.UserId, which holds the user's id.

Without a user

A request with no user still carries every property of the endpoint's set, with empty values, and an empty Http.User.UserId. That is how an anonymous request looks like on an endpoint that allows one, and what a request from an unknown, disabled or unassigned token looks like there too; on an endpoint that requires authentication such a request is refused before the integration runs. An integration that must treat anonymous callers differently tests Http.User.UserId for an empty value in a Map.