Skip to content

All endpoints unauthenticated with CSRF disabled - unauthenticated Salesforce restore #1

@consigcody94

Description

@consigcody94

Found via code audit. config/SecurityConfig.java:31-38. anyRequest().permitAll() + csrf().disable(). /api/restore writes to Salesforce. /api/download-url generates presigned S3 URLs. Zero auth.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions