From 960efd86baac7aa7bc3788031df4d7681071f282 Mon Sep 17 00:00:00 2001 From: Andrey Savchenko Date: Wed, 26 Dec 2018 17:57:56 +0200 Subject: [PATCH] Improved info about API authentication in readme. --- README.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 3478d47..fa584c7 100644 --- a/README.md +++ b/README.md @@ -28,10 +28,14 @@ Laps automatically tracks many events, such as: For Ajax and REST API — Laps outputs performance information by Server Timing API, for use with clients such as Chrome Dev Tools. -Note that REST API requests need nonce, to be fully authenticated with cookies, to show the information. Alternately `laps_can_see` check can be filtered. - ![Laps v3 dev tools screenshot](https://i.imgur.com/hkl1Qk9.png) +### API authentication + +API requests need to be authenticated as admin for performance data to be sent. For Ajax requests cookies are sufficient. REST API requests also [need nonce passed](https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/#cookie-authentication). + +`laps_can_see` check can be filtered to relax required permissions on the plugin’s side. + ## Installation | [Composer](https://getcomposer.org/) (recommended) | Release archive |