mercedes-benz / sechub

SecHub provides a central API to test software with different security tools.
https://mercedes-benz.github.io/sechub/
MIT License
259 stars 58 forks source link

Remove SecHub configuration from all REST end points of PDS #3268

Open de-jcup opened 2 days ago

de-jcup commented 2 days ago

Situation

With #3266 there will be a dedicated REST endpoint to fetch masked SecHub configuration (as user of the project or as administrator).

It shall be the only possible way to fetch these information. But it could be possible the we provide the configuration at some existing PDS REST end points

:information_source: This is a sub issue of #3250

Wanted

No REST endpoint at PDS shall provide the SecHub configuration

Solution

Check all REST end points if configuration is provided accidentally and remove the information there