lotusbase / lotus.au.dk

Lotus Base website
https://lotus.au.dk
MIT License
2 stars 1 forks source link

Fix leaky admin API #26

Closed terrymun closed 6 years ago

terrymun commented 6 years ago

The admin API currently does not check for user authentication properly, resulting in possibility to modify data externally via a non-authenticated client.