Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[QUESTION] Make config.yml inaccessible from browser #1691

Open
4 tasks done
Grishkaone opened this issue Sep 15, 2024 · 0 comments
Open
4 tasks done

[QUESTION] Make config.yml inaccessible from browser #1691

Grishkaone opened this issue Sep 15, 2024 · 0 comments
Assignees
Labels
🤷‍♂️ Question [ISSUE] Further information is requested

Comments

@Grishkaone
Copy link

Question

Hello there !

I'm new to Dashy, and I love it. I'm testing the authentification system and something is annoying me.

I particularly like the authentication system and the ability to show or hide certain elements to guests or authenticated users.
For example, I can include a section with bookmarks to local IPs that I don't want displayed to just anyone, that's great.

But one detail bothers me: even if I decide to hide these sections, their content can still be easily consulted by a guest. Either from the main menu, by clicking on the name of the configuration file at the bottom of the popup, or by directly opening the address my.dashboard.com/config.yml.

Hiding or not hiding these elements is only aesthetic and does not protect them.

I've already added a bit of CSS to hide the link in the menu, but that doesn't solve everything.

I feel like I'm missing something: is there a way to make the contents of this file inaccessible to non-admin users and guests? Without cutting off the possibility of consulting/editing the configuration from the UI for an administrator.

Have a nice day !

Category

Authentication

Please tick the boxes

@Grishkaone Grishkaone added the 🤷‍♂️ Question [ISSUE] Further information is requested label Sep 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🤷‍♂️ Question [ISSUE] Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants