<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to secure the login API in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/how-to-secure-the-login-api/m-p/53469#M19941</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the security test of our instance our security expert asked us to secure the login API&amp;nbsp;&lt;/P&gt;&lt;PRE class="" style="color: #000000; background: #f5f2f0; border: 0px; margin: 0.5em 0px; padding: 1em 1em 1em 3.8em;"&gt;&lt;CODE style="border: 0px; font-weight: inherit;"&gt;&lt;A class="" href="http://www.myserver.com:8080/alfresco/service/api/login?u=me&amp;amp;pw=mypassword" rel="nofollow noopener noreferrer" style="color: #0d47a1; border: 0px; font-weight: inherit; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;" target="_blank"&gt;http://www.myserver.com:8080/alfresco/service/api/login?u=me&amp;amp;pw=mypassword&lt;/A&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as it send the username and password as it is and can be used by attacker to forge the request login if the admin password is known.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me how we can secure this API or in my case I can disable it also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Hiten Rastogi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2018 07:17:26 GMT</pubDate>
    <dc:creator>hiten_rastogi1</dc:creator>
    <dc:date>2018-05-21T07:17:26Z</dc:date>
    <item>
      <title>How to secure the login API</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-secure-the-login-api/m-p/53469#M19941</link>
      <description>Hi All,During the security test of our instance our security expert asked us to secure the login API&amp;nbsp;http://www.myserver.com:8080/alfresco/service/api/login?u=me&amp;amp;pw=mypasswordas it send the username and password as it is and can be used by attacker to forge the request login if the admin passwor</description>
      <pubDate>Mon, 21 May 2018 07:17:26 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-secure-the-login-api/m-p/53469#M19941</guid>
      <dc:creator>hiten_rastogi1</dc:creator>
      <dc:date>2018-05-21T07:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to secure the login API</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-secure-the-login-api/m-p/53470#M19942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Configure your system to use HTTPS / SSL only, and use a proxy / gateway to disallow the use of the GET-based login operation. The POST-based login operation (same URL, only using JSON post body instead of URL parameters) should be the only one allowed to avoid username / password to appear in any access logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 09:05:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-secure-the-login-api/m-p/53470#M19942</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2018-05-21T09:05:19Z</dc:date>
    </item>
  </channel>
</rss>

