Hi All,
During the security test of our instance our security expert asked us to secure the login API
http://www.myserver.com:8080/alfresco/service/api/login?u=me&pw=mypassword
as it send the username and password as it is and can be used by attacker to forge the request login if the admin password is known.
Can anyone tell me how we can secure this API or in my case I can disable it also.
Thanks
Hiten Rastogi
Configure your system to use HTTPS / SSL only, and use a proxy / gateway to disallow the use of the GET-based login operation. The POST-based login operation (same URL, only using JSON post body instead of URL parameters) should be the only one allowed to avoid username / password to appear in any access logs.
Ask for and offer help to other Alfresco Content Services Users and members of the Alfresco team.
Related links:
By using this site, you are agreeing to allow us to collect and use cookies as outlined in Alfresco’s Cookie Statement and Terms of Use (and you have a legitimate interest in Alfresco and our products, authorizing us to contact you in such methods). If you are not ok with these terms, please do not use this website.