Hi all,
Per the security requirements of the team I am working with, there can't be any kind of external API access. So far the best way to solve this, that I have came up with, is to block that at the Apache Proxy (different VM) level for anything that's an external IP. IE, I have this in my Apache Virtual Host:
<Location "/rest/api/2/" >
Order Deny,Allow
Deny from all
Allow from 10.
</Location>
Initial testing looks good, but are there any ramifications I am not thinking of? Could it potentially break any Add-ons, for example?