uo-lca / CalRecycleLCA

CalRecycle Used Oil LCA Online Tool
Other
0 stars 0 forks source link

Security issue for /config routes #245

Open bkuczenski opened 9 years ago

bkuczenski commented 9 years ago

The /config routes should not be publicly accessible because they allow a user to create and modify ScenarioGroups and view and change the ownership of scenarios.

Ryan has proposed the use of IIS request filtering, using hidden segments but that does not seem to allow for any exceptions, such as a configured "whitelist" of clients who are allowed to execute the commands.

The problem could also be solved with proper authentication / authorization.

More thoughts needed