Project

General

Profile

Actions

action #18594

closed

[tools][sprint 201712.1][bonus] Worker page is accessible without logging in

Added by szarate about 7 years ago. Updated over 6 years ago.

Status:
Resolved
Priority:
Low
Assignee:
Category:
Feature requests
Target version:
Start date:
2017-04-13
Due date:
% Done:

0%

Estimated time:

Description

If an unauthenticated user tries to navigate to one of the worker details page, he can see all the details.

At least he can't modify any of the jobs, but still, while it's not a security issue, i don't think that it should be available for the public, or at least not under /admin (in case we want to allow the public to access this page)

https://openqa.suse.de/admin/workers/141

Actions

Also available in: Atom PDF