Closed mariannemyers closed 7 years ago
Currently the SearchController allows all requests to /v1/ to proxy through. Use a whitelist approach similar to what was done for the slush-marklogic-node project to be more restrictive.
Using a single Route decorator was surprisingly effective for this. Proxy through only valid /v1/ paths.
Currently the SearchController allows all requests to /v1/ to proxy through. Use a whitelist approach similar to what was done for the slush-marklogic-node project to be more restrictive.