I think that's OK, as long as the REST endpoints only bind to localhost
by default. So IMO the real bug here is that we do not do that right now.

Martin: could you add a bind-to option to gnunet-service-rest and
default it to localhost (::1, 127.0.0.1?)?

On 3/9/19 7:52 AM, IC Rainbow wrote:
> On the matter of defaults...
> 
> `gnunet-arm -i rest` would enable world-writtable access to all REST
> API endpoints. It could be changed ofc. But you'll have to know that
> you should do that.

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
GNUnet-developers mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/gnunet-developers

Reply via email to