SAP-archive / bot-connector

Bot Connector allows you to connect your bot to multiple messaging channels.
MIT License
184 stars 101 forks source link

No route protection #26

Closed RalliPi closed 6 years ago

RalliPi commented 6 years ago

There aren't any security mechanisms at all. It seems as everybody can send requests to create new bots ir change endpoints. Or am I missing something?

dbousque commented 6 years ago

In this open source version, it is correct to say that there are no security mechanisms (apart from knowing required ids). You can however very easily add an authentication middleware.