Security Advisory - 08/08/2018

15 views
Skip to first unread message

Taranveer Virk

unread,
Aug 9, 2018, 1:19:40 PM8/9/18
to LoopBackJS Announcements
LoopBack Security Advisory (8/8/2018) => The default ACL for AccessToken model has security concerns. If the model is explicitly exposed as a REST API, anyone can create a token. By default, the model is PRIVATE and there is NO RISK. More details at https://loopback.io/doc/en/lb3/Security-advisory-08-08-2018.htmlhttps://loopback.io/doc/en/lb3/Security-advisory-08-08-2018.htmlhttps://loopback.io/doc/en/lb3/Security-advisory-08-08-2018.html
Reply all
Reply to author
Forward
0 new messages