Skip to content

Deny anonymous users access to CKE endpoints#6706

Merged
bdukes merged 1 commit intodnnsoftware:developfrom
bdukes:deny-anonymous
Sep 16, 2025
Merged

Deny anonymous users access to CKE endpoints#6706
bdukes merged 1 commit intodnnsoftware:developfrom
bdukes:deny-anonymous

Conversation

@bdukes
Copy link
Copy Markdown
Contributor

@bdukes bdukes commented Sep 16, 2025

Summary

As a defense-in-depth strategy, we realized that only in very exceptional circumstances does there need to be anonymous access to upload files via the CKEditor. This PR adds a web.config level denial of access to the CKEditor upload endpoints for anonymous users.

Thanks @r90727 for calling this out and the initial implementation.

Co-authored-by: r90727 <r90727@users.noreply.github.com>
@bdukes bdukes added this to the 10.1.1 milestone Sep 16, 2025
@bdukes bdukes enabled auto-merge (rebase) September 16, 2025 21:04
Copy link
Copy Markdown
Contributor

@donker donker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome

@bdukes bdukes merged commit 6497d3c into dnnsoftware:develop Sep 16, 2025
3 checks passed
@bdukes bdukes deleted the deny-anonymous branch September 16, 2025 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants