Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Flaw #859

Open
supersaiyane opened this issue Dec 9, 2021 · 1 comment
Open

Security Flaw #859

supersaiyane opened this issue Dec 9, 2021 · 1 comment
Labels
bug Something isn't working

Comments

@supersaiyane
Copy link

Open Config for Flagr

  1. Flagr URL is accessible without authentication
  2. Without Authentication global application configs can be changed/deleted.

To Reproduce

  1. Go to domain/config

Expected behavior
All the exposed service should be password protected like Keycloak

Screenshots
divoc-demo-flagr

@supersaiyane supersaiyane added the bug Something isn't working label Dec 9, 2021
@dileepbapat
Copy link
Collaborator

@supersaiyane for demo instance / docker-compose file auth config (jwt) is not set as of now, can be configured at https://github.com/egovernments/DIVOC/blob/main/docker-compose-release.yml#L70
configuration documentation :
https://checkr.github.io/flagr/#/flagr_env

Usually this may use dedicated role or even different auth provider based on implementation need.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants