Description
The Swagger API documentation at /api/docs is exposed unconditionally in all environments.
Risk: In production, this exposes:
- All API endpoints and their schemas
- Authentication mechanisms
- A detailed attack surface map
Tasks
Tasks:
Visual Aids
No response
Description
The Swagger API documentation at /api/docs is exposed unconditionally in all environments.
Risk: In production, this exposes:
Tasks
Tasks:
Visual Aids
No response