jasonwryan

Members
  • Content Count

    3
  • Joined

  • Last visited

About jasonwryan

  • Rank
    New User
  1. Thanks for checking: returning a single folder was indeed a fault with my setup. My second concern remains unaddressed, AFAICT.
  2. According to the documentation for get_folders: However, specifying a secret just return the same (full) folder list, not just the details of the folder corresponding to the secret.Of more concern is the fact that, without the password option enabled in your .conf, this query returns all of your secrets without requiring any authentication. This strikes me as a potential vulnerability. Surely a secret should be provided before this sort of sensitive information is returned?