Skip to content
This repository has been archived by the owner on Sep 8, 2023. It is now read-only.

Workspace does not require authentication #1117

Open
viharm opened this issue Jan 12, 2020 · 1 comment
Open

Workspace does not require authentication #1117

viharm opened this issue Jan 12, 2020 · 1 comment

Comments

@viharm
Copy link

viharm commented Jan 12, 2020

I have been a long time user of Codiad and I love it, especially when combined with CodeGit.

However I have stumbled into a potential security issue.

I have setup external LDAP authentication to protect my instance of Codiad. However irrespective of which authentication source is used, it only protects Codiad's files. This authentication mechanism does not protect the project files in the workspaces.

I have tried to access some of my project's PHP scripts in the workspace area BASE_PATH/workspace/myproject/example.php and they work without having to login using Codiad's login page.

Is this by design? Shouldn't the workspaces and projects be secured with Codiad's security/login mechanisms? After all they reside within Codiad. Is there something I'm missing?

@basteyy
Copy link
Contributor

basteyy commented Feb 9, 2020

Yep, its by design.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants