Skip to content

Conversation

@grich88
Copy link

@grich88 grich88 commented Oct 15, 2025

…endpoint

  • Require authentication for accessing flags endpoint
  • Require admin role for sensitive configuration access
  • Filter sensitive data (AUTH0_DOMAIN, AUTH0_APP_CLIENT_ID, SAML_AUTH_ACS_URL, etc.)
  • Prevent information disclosure vulnerability

Fixes: #307

…endpoint

- Require authentication for accessing flags endpoint
- Require admin role for sensitive configuration access
- Filter sensitive data (AUTH0_DOMAIN, AUTH0_APP_CLIENT_ID, SAML_AUTH_ACS_URL, etc.)
- Prevent information disclosure vulnerability

Fixes: AIxBlock-2023#307
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HIGH: Configuration Information Disclosure on workflow.aixblock.io

1 participant