We have an integration in our system where it is possible as a client to create a shareable short url when the client is on an article. We have found that it is possible to get the API access token with a network inspection tool, and then submit requests to create short urls with our domain.
It seems that one solution is to restrict what destinations are possible.
Therefore I would like to be able to define a whitelist of domains that can be used as target URLs, so that we can avoid someone hijacking the API keys and create custom urls using our custom domain to destination outside our control, like https://www.attacker.com
Please authenticate to join the conversation.
Planned
💡 Feature Request
5 months ago

Ian from Saxo
Get notified by email when there are changes.
Planned
💡 Feature Request
5 months ago

Ian from Saxo
Get notified by email when there are changes.