Project

General

Profile

Actions

Feature #40914

closed

Feature #40907: mgr/dashboard: REST API improvements

mgr/dashboard: REST API: security

Added by Ernesto Puerta almost 5 years ago. Updated about 3 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
General - Back-end
Target version:
-
% Done:

0%

Source:
Tags:
security
Backport:
nautilus, octopus
Reviewed:
Affected Versions:
Pull request ID:

Description

The following measures should be implemented:
- Failed login limit (after that, the user will be disabled).
- Rate limiting: per-user/token.
- Cache-control private for every response containing personal sensitive information.


Related issues 4 (1 open3 closed)

Related to Dashboard - Feature #39999: mgr/dashboard: Prevent brute-force/dictionary attacks against existing local user accountsResolvedNizamudeen A

Actions
Blocks Dashboard - Feature #47765: mgr/dashboard: security improvementsNew

Actions
Copied to Dashboard - Backport #48794: octopus: mgr/dashboard: REST API: securityResolvedNizamudeen AActions
Copied to Dashboard - Backport #48795: nautilus: mgr/dashboard: REST API: securityRejectedActions
Actions

Also available in: Atom PDF