Aperto Chiuso

External Provider API is exposing key value #2743


User avatar
0
shobhit creato
  • ABP Framework version: v4.2.2
  • UI type: Angular
  • DB provider: EF Core
  • Tiered (MVC) or Identity Server Separated (Angular): yes
  • Exception message and stack trace:
  • Steps to reproduce the issue:"
  1. access api url: https://myapi.com/api/account/external-provider/by-name?Name=<provider> like Google
  2. user can get all details about external provider configuration
  3. this is not secured

1 risposte
  • User Avatar
    0
    maliming creato
    Team di supporto Fullstack Developer

    user can get all details about external provider configuration

    these are public info not including the secrets.

Made with ❤️ on ABP v8.2.0-preview Updated on marzo 25, 2024, 15:11