Skip to content

Security issue: API should not be available via plain HTTP #321

Description

@leandrosansilva

First of all, thank you a lot for offering such service as an alternative to the paid IMDB API.

I just created an key to play around the API and noticed that all the interaction has been done via plain HTTP connections, from browsing the website, submitting the key registration form, and activating the key.

Luckily I used a disposable e-mail address.

In practical terms, using plain HTTP means that the sensitive information is public, no longer being sensitive, which is a huge security issue. This is IMO a severe security issue.

Awkwardly enough, the API, as well as the website do work over HTTPS, which prevents such security issues (at least on the public side of the application), so I really believe the documentation should change to tell users to simply use the https:// version of the endpoints.

Furthermore, the http endpoints could IMO be disabled, maybe even returning an error warning the users that their keys have been leaked and that they should change create a new key and use the HTTPS endpoints. I don't think a HTTP redirect suffices here in terms of security.

Evidence:

image

image

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions