Skip to content

Off-box captain serve routes bypass token authentication #93

Description

@adityathebe

captain serve documents that off-box requests require a token, but token authentication applies only to /api/v1 and /git. Other API routes remain reachable without a token when the server listens beyond loopback, including chat, attachments, session and prompt controls, tasks, and Kubernetes Secret and ConfigMap metadata.

Remote callers can therefore access host-backed Captain capabilities despite the server being configured for token-authenticated remote use.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions