When i type in my browser: http://grav.xxxxxxxxx.pl/admin/config/site i have access to Configuration Site without login (after logout), i can read admin -email ,serwer data, settings of page, isn't this a fatal error of Grav? :/
Archive
Hmm.. we recently changed the routes for those (1.0.7 I think) and it seems the security access checks were not updated. I have created an issue for this and we will get that sorted ASAP!
https://github.com/getgrav/grav-plugin-admin/issues/397
Thanks for finding this!
Ok, fixed and released 1.0.7 of Admin to address this. Thanks again.
Log in to reply.
Suggested topics
| Topic | Participants | Replies | Views | Activity |
|---|---|---|---|---|
| 0 | 1354 | 9 years ago | ||
| 2 | 935 | 9 years ago | ||
| 2 | 4065 | 9 years ago | ||
| 1 | 2953 | 9 years ago | ||
| 3 | 1119 | 9 years ago |