Repository navigation
[FEATURE] Expose installed Tinyauth version via /api/context/app API endpoint #1160
Description
Activity
Hello @crivchri,
Yep that does sound like a good idea. Although it would have to be protected, not available to everyone. This is because a version of Tinyauth may include a specific vulnerability and a public version endpoint gives an attacker an easy way to see if any vulnerabilities are present in that version.
Hello @crivchri,
Yep that does sound like a good idea. Although it would have to be protected, not available to everyone. This is because a version of Tinyauth may include a specific vulnerability and a public version endpoint gives an attacker an easy way to see if any vulnerabilities are present in that version.
Hi @steveiliop56,
You're absolutely right. I was under the impression that the
/api/context/appendpoint was protected, but it turns out it isn't.
Do you think this endpoint should be protected, as it returns other sensitive information?Kind regards.
Nope, the app context endpoint is public by design to provide the necessary information for the fontend to work for unauthenticated users.
Nope, the app context endpoint is public by design to provide the necessary information for the fontend to work for unauthenticated users.
Hi @steveiliop56,
Is there another protected endpoint, which could expose the version?
Yep, we can do it at the
/api/user/contextendpoint or we can just add a new protected endpoint for/api/version(I will probably do the second one).Yep, we can do it at the
/api/user/contextendpoint or we can just add a new protected endpoint for/api/version(I will probably do the second one).Hi @steveiliop56,
Sounds great, thank you.
Could this be implemented by next release?Thank you in advance and kind regards!
Will try to include it if I have time.
Reacted by crivchriOpened #1181 for this: a protected
GET /api/versionthat returns the running version only to an authenticated user (anonymous requests get the standard 401), so the version is not publicly exposed.Reacted by crivchri
Is your feature request related to a problem? Please describe.
I use Argus to monitor GitHub releases, and I am always frustrated that the
/api/context/appAPI endpoint does not return the currently installed Tinyauth version.Describe the solution you'd like.
I would suggest to add the Tinyauth version to the
/api/context/appendpoint.This would allow tools such as Argus to reliably determine the installed version and notify users about available updates.
Thank you for considering this feature request and kind regards!
Describe alternatives you've considered.
No response
Additional context
No response
Human Written Confirmation