agusmakmun / agusmakmun/django-markdown-editor

markdownfy_view is unauthenticated - Please consider changing it

未关闭
#194 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
901
派生
1.3k
PR 合并指标
30 天内没有已合并 PR

描述

Currently the installation document/README just says add URLs to your Django. No issues with this part. What is not specified here is that the URL `/martor/markdownify/` now becomes "public". By itself, it is not a problem. There maybe many "mitigating" circumstances such as ALBs that don't allow `/martor/` URLs and such. But, if someone were to just directly deploy this without reading the code, they have unintentionally exposed an _unauthenticated_ URL.

Either we should call it out explicitly in the README, or better yet, there should be no reason for the function `markdownfy_view` to not have the `login_required` decorator which all the other functions have.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。