Skip to content
This repository has been archived by the owner on Jan 31, 2019. It is now read-only.

Security Risk - push command adds db url from .kansorc to the design doc. #409

Closed
ozomer opened this issue Jul 1, 2014 · 1 comment
Closed

Comments

@ozomer
Copy link
Contributor

ozomer commented Jul 1, 2014

push.js line 124

The design doc is created with a kanso.config._url field that contains the url from the .kansorc file.

Following the explanation here, it is recommended to put the username and password in the .kansorc file (and add it to .gitignore).

This will be very bad if your couchdb has public read access...

@ryanramage

ozomer added a commit to ozomer/kanso that referenced this issue Aug 2, 2014
mandric added a commit that referenced this issue Aug 19, 2014
Issue #409: Remove auth from url.
@mandric
Copy link
Member

mandric commented Jan 2, 2015

This was fixed in 0.4.0.

@mandric mandric closed this as completed Jan 2, 2015
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants