cancel
Showing results for 
Search instead for 
Did you mean: 

REST API : access to encrypted (or not) user passwords

pibou_Bouvret
Elite Collaborator
Elite Collaborator

I m into coding a one page application using the REST API, Auth being managed by token auth. I was quite surprised to discover that the user endpoint gives access to users passwords to any user using the API ! Could this user attribute be reserved to admin accounts just like in the web UI ?

1 REPLY 1

Florent_Guillau
World-Class Innovator
World-Class Innovator

Hi,

A fix for this is included in Nuxeo 6.0-HF31, you should apply the hotfix.

Getting started

Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.