Set Function Policy
set_function_policyCreate or update the server-owned access policy of a backend function (functions/.js). Without a policy a function answers only to the app owner's Studio token (401 for app visitors and webhooks). Recipes: anonymous checkout step or inbound webhook/IPN -> require_auth=false; signed-in members -> require_auth=true + allowed_roles (e.g. ['authenticated'] or ['admin','staff']); webhook with a shared secret -> require_secret=true + secret_name (an app secret) that the caller sends in secret_header. allowed_hosts fences the function's outbound network to those hosts plus the platform backend; omit it for open egress.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| app_id | Yes | The app ID | |
| function | Yes | Function name, e.g. takbull_create (file functions/takbull_create.js) | |
| secret_name | No | Name of the app secret holding the shared value (set_secret) | |
| require_auth | Yes | false = anonymous visitors and external callers may invoke | |
| sdk_identity | No | Whose identity the SDK inside the function uses. 'caller' (default): the function reads data as whoever called it, so an anonymous call sees only what anonymous may read. 'app': the SDK acts as the app owner on THIS app's entities (a checkout or payment IPN that must load/update orders whose read policy is owner/admin/staff); the caller still counts as anonymous for rate limits, audit and X-FSe2-Caller-Type. Owner-only. Omit to keep the stored value | |
| allowed_hosts | No | Outbound egress allow-list of host[:port] entries, e.g. ['api.takbull.co.il']. Omit to keep the stored list; pass [] to open egress again | |
| allowed_roles | No | App roles allowed when require_auth is true; 'authenticated' = any signed-in app member | |
| secret_header | No | Header the caller sends the shared secret in | x-fse2-secret |
| require_secret | No | Caller must send a shared secret header (webhooks) |