Skip to content
This repository has been archived by the owner on Dec 12, 2021. It is now read-only.

Secret key #4

Open
ryanb opened this issue Jun 22, 2009 · 0 comments
Open

Secret key #4

ryanb opened this issue Jun 22, 2009 · 0 comments

Comments

@ryanb
Copy link
Owner

ryanb commented Jun 22, 2009

The xapit/reload controller action is public and accessible to everyone. This should be protected and require some kind of authorization so the public users cannot trigger it.

This should be possible with a simple key setting. Maybe like this:

XapitSync.private_key = "alsdhskdfhlizhzlsdfhkwe"

If this exists then it is required that this be specified in the URL when triggering xapit controller actions.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant