Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow apilogs to be Protected by a Guard #13

Open
lloy0076 opened this issue Sep 30, 2019 · 4 comments
Open

Allow apilogs to be Protected by a Guard #13

lloy0076 opened this issue Sep 30, 2019 · 4 comments
Labels
enhancement New feature or request

Comments

@lloy0076
Copy link
Contributor

It seems at the moment that any user can see the logs (in /apilogs); obviously this could be a security issue.

It could be optional to protect that route(s) with a guard (which could be configurable).

@aungwinthant
Copy link
Owner

I am thinking about it too. I'll handle this one.

@aungwinthant aungwinthant added the enhancement New feature or request label Sep 30, 2019
@mtveerman
Copy link

This is a must. Else detailed info, and info valuable with regards to marketing (e.g number of requests or day) is visible to public.

I was thinking the requesting user id should also be logged, in which case the apilogger view definitely needs to be guarded.

(Look at how larecipe guards and defined it's routes. Not that hard)

@aungwinthant
Copy link
Owner

Thanks I will definitely look into it.

@dansleboby
Copy link
Contributor

Added in #42

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants