SURFscz / SBS

Samenwerking Beheer Systeem ↣ Collaboration Management System
Apache License 2.0
3 stars 2 forks source link

Protect SCIM resource endpoints #1457

Closed HarryKodden closed 4 weeks ago

HarryKodden commented 4 weeks ago

at this moment the SCIM endpoints: https://sram.surf.nl/api/scim/v2/Users/\<sram identifier> and https://sram.surf.nl/api/scim/v2/Groups/\<sram identifier> are publicly accessible.

Although the SRAM Identifiers are not easy guessable, we would like these endpoints protected

baszoetekouw commented 3 weeks ago

works