Make getState API unavailable for unauthorized machines
Following on Marcin's response, we need to tighten up getState API command. Here's the original issue:
- start the demo
- go to machines, show unauthorized
- click on the machine name (I used agent-kea-ha2)
- click on the get latest state
This scenario is no longer possible from the UI as Marcin blocked the GetState button, but it's still possible using API. There should be an API check that would fail if machine is not authorized.