`api.config.auto-save.get` route returns data without any authentication

Created on 23 June 2025, about 5 hours ago

Overview

The experience_builder.api.config.auto-save.get route returns data of js_component and xb_asset_library entities without any authentication. This has been the case since πŸ› Content authors cannot see components Active landed.

Proposed resolution

Restrict access properly.

User interface changes

n/a

πŸ› Bug report
Status

Active

Version

0.0

Component

… to be triaged

Created by

πŸ‡³πŸ‡±Netherlands balintbrews Amsterdam, NL

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024