Skip to content

Commit 8c10b95

Browse files
committed
chore: narrow API whitelist for shares to GET
1 parent bee88b8 commit 8c10b95

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

manifests/components/auth/secret-params.env

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
1-
# TODO: how to allow only GET /api/shares/{share_id}?
2-
OAUTH2_PROXY_SKIP_AUTH_ROUTES=/metrics,/share/.*,/api/shares/.*,/static/.*,/favicon.ico,/manifest.json
1+
OAUTH2_PROXY_SKIP_AUTH_ROUTES=/metrics,/share/.*,GET=/api/shares/.*,/static/.*,/favicon.ico,/manifest.json
32
OAUTH2_PROXY_COOKIE_SECRET=tNTtR9Rz4XWkUL4BL7bDghPK0Ck8PrQAagrWwqr2LNI=
43
OAUTH2_PROXY_EMAIL_DOMAINS=*
54
OAUTH2_PROXY_SESSION_STORE_TYPE=redis

0 commit comments

Comments
 (0)