Job Data exposes Authorization token #4530
Closed
LucidityDesign
started this conversation in
Feature Requests
Replies: 1 comment
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
When passing the RequestContext to a new job, the authorization token will be stored with the job and exposed on the Job Queue page.
This enables admins to impersonate other admin accounts.
The documentation mentions how passing the RequestContext can be streamlines however it's difficult so understand which information is relevant for the specific use-cases.
Possible Solutions
ctx.serialize()might help omitting unnecessary data. This could be an array of keys e.g.ctx.serialize(['channelToken', 'languageCode'])but there are probably better aproaches.All reactions