Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security tightened for API and Client communication #37

Open
emettely opened this issue Jul 4, 2019 · 0 comments
Open

Security tightened for API and Client communication #37

emettely opened this issue Jul 4, 2019 · 0 comments

Comments

@emettely
Copy link
Contributor

emettely commented Jul 4, 2019

Context

The security for the API is completely loose right now for easier experimentation. We do not yet have any business critical data in the API. However this will change and we should tighten communication of the API.

Issues relating to this:
bbc/digital-paper-edit-api#7

Todo

  1. Revert changes in bbc/digital-paper-edit-api@ad0e351 to be like this: bbc/digital-paper-edit-api@b9d30f1
  2. set up requests using certs in the Client. This would imply that the cert is an optional environment variable.
@emettely emettely created this issue from a note in BBC News Labs - (0) Digital Paper Edit - Sprint Board (Backlog) Jul 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
No open projects
Development

No branches or pull requests

1 participant