Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Protected auth methods are exposed in the /apis/.../swagger endpoint #198

Closed
DonMartin76 opened this issue May 29, 2019 · 0 comments
Closed
Labels
Milestone

Comments

@DonMartin76
Copy link
Member

In case you are using "protected" auth methods, these are currently inadvertently exposed in the /apis/.../swagger endpoint, thus are offered for use in the Swagger UI. This should quite obviously not be the case.

@DonMartin76 DonMartin76 added this to the 1.0.0-rc.6 milestone May 29, 2019
maksimlikharev pushed a commit to clarivate/wicked.api that referenced this issue Jun 7, 2019
* adding group for the subscription/approval events (#22)

* Bump to version 1.0.0-rc.5

* Fixes Haufe-Lexware/wicked.haufe.io#196

* Fixes Haufe-Lexware/wicked.haufe.io#198

* Bump to version 1.0.0-rc.6

* Update docker group to adapt to new Jenkins

* Use classical pipeline again (test)

* Try this on the RD jenkins

* Allow loading of javascript file in static content (#24)

* Change back to "docker" agent

* Take out SonarQube for the time being
maksimlikharev pushed a commit to clarivate/wicked.api that referenced this issue Jul 29, 2019
* adding group for the subscription/approval events (#22)

* Bump to version 1.0.0-rc.5

* Fixes Haufe-Lexware/wicked.haufe.io#196

* Fixes Haufe-Lexware/wicked.haufe.io#198

* Bump to version 1.0.0-rc.6

* Update docker group to adapt to new Jenkins

* Use classical pipeline again (test)

* Try this on the RD jenkins

* Allow loading of javascript file in static content (#24)

* Change back to "docker" agent

* Take out SonarQube for the time being

* Log in once to make sure docker login is done

* Bump to version 1.0.0-rc.7

* Enable switching off health checks

* Bump to version 1.0.0-rc.8

* Infinite loop inside docker container...
... instead of letting e.g. Kubernetes handle the restart. Advantages:
- Much quicker restart
- Kubernetes does not count a reload as a full crash

See Haufe-Lexware/wicked.haufe.io#212

* honor host (#25)

* Partly fixes Haufe-Lexware/wicked.haufe.io#216
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant