34b71e734b
- To prevent an attacker from enumerating the `/users` API to get a list of all the admins. - Display the `is_admin?` flag wherever we display the `private_token` - at the moment, there are two instances: - When an admin uses `sudo` to view the `/user` endpoint - When logging in using the `/session` endpoint |
||
---|---|---|
.. | ||
public_api | ||
board.json | ||
boards.json | ||
conflicts.json | ||
issue.json | ||
issues.json | ||
list.json | ||
lists.json |