Skip to content

Is it safe to specify errors plugin before scope auth plugin? #467

Answered by hayes
knpwrs asked this question in Q&A
Discussion options

You must be logged in to vote

Yes, provided the content of your errors are not sensitive. Basically the error types in the response mah not be protected by authorization checks, but I think for all cases I can think of this is okay. You should still be able to add authorization checks to specific fields of the error types if they need to be protected as well.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by hayes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #464 on July 12, 2022 01:10.