api-platform / api-platform/core
Make hydra documentation respect access control
オープン
- 主要言語
- PHP
- スター
- 2.6k
- フォーク
- 980
- 平均マージ
- 2日 5時間
- マージ済み PR(30日)
- 48
説明
My api has public and private entries.
But the hydra and swagger documentations expose all of them.
As a result, a connected user that has access to only parts of the api will see the whole documentation which is not a good thing for security.
More importantly, the admin is broken in that case because it tries to fetch every resource in the hydra documentation.
コントリビューションガイド
評価
この issue はまだ評価されていません。