Skip to content

Settings are accessible to anonymous users #1412

@brylie

Description

@brylie

Our Settings are published to the client, even for anonymous users, and include the following fields:

  • apiUmbrella
    • authToken
    • apiKey
    • baseUrl
  • elasticsearch url

These settings can be abused, so should be handled more carefully.

Steps to reproduce

  1. visit the home page as an anonymous user
  2. open the browser console
  3. search the Settings collection for a single document

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions