Why 'reset' route is not limited to local env ? #299
Replies: 1 comment
-
|
Thanks for reporting this. Should be fixed now! |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I noticed that the following route: Route::get('reset', Reset::class); is publicly accessible — it isn’t restricted to a local environment or to authenticated users.
It might be safer to limit access to this route (for example, by wrapping it with an environment or authentication check).
Beta Was this translation helpful? Give feedback.
All reactions