agusmakmun / agusmakmun/django-markdown-editor

markdownfy_view is unauthenticated - Please consider changing it

Abierto
#194 1 comentario 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
JavaScript
Estrellas
901
Forks
1.3k
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Currently the installation document/README just says add URLs to your Django. No issues with this part. What is not specified here is that the URL `/martor/markdownify/` now becomes "public". By itself, it is not a problem. There maybe many "mitigating" circumstances such as ALBs that don't allow `/martor/` URLs and such. But, if someone were to just directly deploy this without reading the code, they have unintentionally exposed an _unauthenticated_ URL.

Either we should call it out explicitly in the README, or better yet, there should be no reason for the function `markdownfy_view` to not have the `login_required` decorator which all the other functions have.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.