Project

General

Profile

Actions

User story #2322

closed

Forbid access to URL /api/* for any hosts safe localhost

Added by François ARMAND about 12 years ago. Updated about 9 years ago.

Status:
Released
Priority:
1
Assignee:
Matthieu CERDA
Category:
Packaging
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

In Rudder, URL under /api/* are REST api that allows to do a lot of thing but do not require authentication if rudder-web.properties property rudder.rest.allowNonAuthenticatedUser is set to true (default).

But we want to allow access to these URL only from localhost.

=> change Apache configuration to forbid that !

Actions

Also available in: Atom PDF