Deactivate api-doc access for all registered users by default
Over many years, all "Registered Users" got per default access to /api-doc. T…
Show more
Deactivate api-doc access for all registered users by defaultOver many years, all "Registered Users" got per default accessto /api-doc. This is probably OK, when one assumes that theregistered users are developers. However, providing source codeaccess to all registered users can pose a security thread,especially on large sites.For new installs, api-doc is now just accessible for site-wide admins.Providing more liberal rights for users can be achieved viasetting the permissions via the sitemap.
Show less