You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Expected behavior
/stats should only be available with the given api key, maybe even by default disabled
Server (please complete the following information):
Etherpad version: 2.0.1-2.2.6, probably also earlier versions affected
OS: container
Is the server free of plugins: yes
Additional Context:
i do believe that exposing /stats while being unauthenticated is a security risk
either apply the logic with the api key
or better in my opinion disable the /metrics endpoint by default
i would favor the later because enabling that endpoint is an explicit action, if you do that, you probably don't want to also expose it in your reverse proxy or similar.
The text was updated successfully, but these errors were encountered:
Describe the bug
A clear and concise description of what the bug is.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
/stats should only be available with the given api key, maybe even by default disabled
Server (please complete the following information):
Additional Context:
i do believe that exposing /stats while being unauthenticated is a security risk
i would favor the later because enabling that endpoint is an explicit action, if you do that, you probably don't want to also expose it in your reverse proxy or similar.
The text was updated successfully, but these errors were encountered: