You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/authentication/api-keys.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -104,7 +104,7 @@ Payload ensures that the same, uniform [Access Control](../access-control/overvi
104
104
105
105
### API Key Only Auth
106
106
107
-
If you want to use API keys as the only authentication method for a collection, you can disable the default local strategy by setting `disableLocalStrategy` to `true` on the collection's `auth` property. This will disable the ability to authenticate with email and password, and will only allow for authentication via API key.
107
+
If you want to use API keys as the only authentication method for a collection, you can disable the default local strategy by setting `disableLocalStrategy` to `true` on the collection's `auth` property. Setting it to `false` keeps local authentication enabled. Disabling the local strategy prevents authentication with email and password, leaving API keys as the collection's authentication method.
Copy file name to clipboardExpand all lines: docs/authentication/custom-strategies.mdx
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,6 +40,8 @@ The `authenticate` function is passed the following arguments:
40
40
41
41
At its core a strategy simply takes information from the incoming request and returns a user. This is exactly how Payload's built-in strategies function.
42
42
43
+
The example below sets `disableLocalStrategy` to `true` because the custom strategy replaces local authentication. Set it to `false` or omit it to keep email and password authentication enabled alongside your custom strategy.
44
+
43
45
Your `authenticate` method should return an object containing a Payload user document and any optional headers that you'd like Payload to set for you when we return a response.
|**`cookies`**| Set cookie options, including `secure`, `sameSite`, and `domain`. For advanced users. |
90
90
|**`depth`**| How many levels deep a `user` document should be populated when creating the JWT and binding the `user` to the `req`. Defaults to `0` and should only be modified if absolutely necessary, as this will affect performance. |
91
-
|**`disableLocalStrategy`**|Advanced - disable Payload's built-in local auth strategy. Only use this property if you have replaced Payload's auth mechanisms with your own. |
91
+
|**`disableLocalStrategy`**|Set to `true` to disable local authentication, `false` (default) to keep it enabled, or an object to retain auth fields while disabling it. [More details](#disable-local-strategy).|
92
92
|**`forgotPassword`**| Customize the way that the `forgotPassword` operation functions. [More details](./email#forgot-password). |
93
93
|**`lockTime`**| Set the time (in milliseconds) that a user should be locked out if they fail authentication more times than `maxLoginAttempts` allows for. |
94
94
|**`loginWithUsername`**| Ability to allow users to login with username/password. [More](/docs/authentication/overview#login-with-username)|
@@ -100,6 +100,27 @@ The following options are available:
100
100
|**`useSessions`**| True by default. Set to `false` to use stateless JWTs for authentication instead of sessions. Stateless JWTs cannot be revoked, so they stay valid until `tokenExpiration` even after a password change. |
101
101
|**`verify`**| Set to `true` or pass an object with verification options to require users to verify by email before they are allowed to log into your app. [More details](./email#email-verification). |
102
102
103
+
### Disable Local Strategy
104
+
105
+
The built-in local strategy authenticates users with an email or username and password. It is enabled by default. Set `disableLocalStrategy` to `true` to disable it, or to `false` to explicitly keep it enabled. Only disable the local strategy if you have configured another authentication method, such as [API keys](./api-keys) or a [custom strategy](./custom-strategies).
106
+
107
+
You can also pass an object to disable the local strategy while retaining its auth fields:
108
+
109
+
```ts
110
+
{
111
+
slug: 'users',
112
+
auth: {
113
+
disableLocalStrategy: {
114
+
enableFields: true,
115
+
optionalPassword: true,
116
+
},
117
+
},
118
+
}
119
+
```
120
+
121
+
-`enableFields` retains the local auth fields in the database and generated types.
122
+
-`optionalPassword` makes the password field optional when auth fields are retained.
123
+
103
124
### Login With Username
104
125
105
126
You can allow users to login with their username instead of their email address by setting the `loginWithUsername` property to `true`.
0 commit comments