Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

/metrics endpoint exposed #52

Open
lothardp opened this issue Sep 28, 2022 · 3 comments
Open

/metrics endpoint exposed #52

lothardp opened this issue Sep 28, 2022 · 3 comments
Assignees
Labels
tracked Issue is tracked in 1Password's internal ticketing system as well.

Comments

@lothardp
Copy link

I have a connect server deployed in a different cloud service than my main app, so I am using Lets Encript to protect the communication from my app to the 1password connect server. I noticed that the /metrics endpoint in the server is publicly available, and it responds with information about the server. I am not sure if you (at 1Password) are aware of this, I don't think this is sensible information but I think it would be better if it wasn't public.

@ag-adampike
Copy link
Member

Hey @lothardp! I can confirm that the /metrics endpoint is available without authenticating, and I likewise suspect that this is not intended.

I'll discuss this with our team internally and update the issue shortly. Thanks for bringing this to our attention.

@ag-adampike
Copy link
Member

We are discussing internally and working on a solution for this. Thanks again for filing the issue!

In the meantime, (if possible) you might consider restricting public traffic to the data endpoints you require.

@ag-adampike ag-adampike added the tracked Issue is tracked in 1Password's internal ticketing system as well. label Sep 29, 2022
@lothardp
Copy link
Author

You're welcome, and thank you for your quick responses and the tip.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
tracked Issue is tracked in 1Password's internal ticketing system as well.
Projects
None yet
Development

No branches or pull requests

3 participants