api-platform / api-platform/core

Make hydra documentation respect access control

未關閉
#2,719 11 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
PHP
星號
2.6k
分支
980
平均合併
2 天 5 小時
30 天內合併 PR
48

描述

My api has public and private entries.

But the hydra and swagger documentations expose all of them.

As a result, a connected user that has access to only parts of the api will see the whole documentation which is not a good thing for security.

More importantly, the admin is broken in that case because it tries to fetch every resource in the hydra documentation.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。