4 ms·
Thanks for that. I have shut off public access to that endpoint and, after reading your post 38 minutes after you posted it, had immediately shut off all access
by arthurhur 3y ago
Thanks for that. I have shut off public access to that endpoint and, after reading your post 38 minutes after you posted it, had immediately shut off all access to the API while I was looking into it.
It was something I was debating before launching because of something Tom Christie mentioned below, and I probably misread it.
> In many cases I think it's a shame that folks would choose to disable the browsable API in any case, as it's a big aid to any developers working on the API, and it doesn't give them more permissions that they would otherwise have. I can see that there might be business reasons for doing so in some cases, but generally I'd consider it a huge asset. Although, in some cases there may be details shown (like the names of custom actions) that a non-public API may not want to expose.
https://stackoverflow.com/questions/11898065/how-to-disable-admin-style-browsable-interface-of-django-rest-framework https://stackoverflow.com/questions/11898065/how-to-disable-...
In the spirit of openness and transparency, I thought it would be a good gesture to open up the API for people to poke around, but I see your point and have turned off that endpoint.
To be fair though, adding a remarq does show your full name to the public, because if you are willing to defend your marq, you should be willing to do it with your real name. The marqt switches, however, only show user handle.
In order to sign up, you only provide three things: full name, username, and email. That endpoint did allow you to see email, so I shut that off. But the other two – full name and username – would be part of any public profile.