[Feature] Strengthen the protection against sniffing of panel resource files #7999
Unanswered
SolomonLeon
asked this question in
Q&A
Replies: 2 comments
-
Thank you for the feedback. Currently, some static resources on the 1Panel login page are allowed for anonymous access. |
Beta Was this translation helpful? Give feedback.
0 replies
-
The issue has been converted to a discussion. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
1Panel Version
v1.10.25-lts
Please describe your needs or suggestions for improvements
The resource files under
assets
can be accessed withoutSecurityEntrance
cookies, this may provide attackers with information, leading to an increase in the attack surface.Please describe the solution you suggest
Return 404 or 500 error unless the correct
SecurityEntrance
cookie is sent.Additional Information
No response
Beta Was this translation helpful? Give feedback.
All reactions