New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[portal] Try-it for anonymous user #222

Closed
brasseld opened this Issue Sep 13, 2016 · 2 comments

Comments

Projects
None yet
2 participants
@brasseld
Member

brasseld commented Sep 13, 2016

It seems that the try-it is enabled for all users including anonymous (non-authenticated) user.
According to me, it shouldn't be the case for security reason.

WDYT ?

@NicolasGeraud

This comment has been minimized.

Member

NicolasGeraud commented Sep 13, 2016

i'm agree,
so we need to remove the button and override the host included in the swagger.json...
Otherwise, users just have to try the api with curl.

Perhaps we have to implement the visibility of the documentation.

@brasseld

This comment has been minimized.

Member

brasseld commented Sep 14, 2016

According to me, we just have to remove or disable the "Try-it" button.

Documentation's visibility will be a new feature in Gravitee.io v4.5.4-build#1421

@NicolasGeraud NicolasGeraud self-assigned this Sep 22, 2016

@NicolasGeraud NicolasGeraud added this to the 0.19.1 milestone Sep 22, 2016

NicolasGeraud added a commit to gravitee-io/gravitee-management-webui that referenced this issue Sep 22, 2016

NicolasGeraud added a commit to gravitee-io/gravitee-management-webui that referenced this issue Sep 22, 2016

brasseld added a commit to gravitee-io/gravitee-management-webui that referenced this issue Sep 22, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment