Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security flaw] private pages cached #34

Open
dragonwocky opened this issue Dec 21, 2020 · 0 comments
Open

[security flaw] private pages cached #34

dragonwocky opened this issue Dec 21, 2020 · 0 comments

Comments

@dragonwocky
Copy link

dragonwocky commented Dec 21, 2020

I have a use case where multiple users will be making use of a tool and so self-hosting and changing the NOTION_TOKEN as recommended wouldn't be a viable solution.

I've been adding the Authorization: Bearer <NOTION_TOKEN> header to my requests to private pages, but have noticed that because those pages are cached for a few seconds I if I then request the same URL without the authorisation header I can load private page data (tested from a separate device, so it's not just browser caching).

Either private pages shouldn't be cached, or their authorisations should be cached with them to prevent this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant