Skip to content

Postgres password visible inside self-hosted dashboard #992

Open
@johanbook

Description

@johanbook

I just updated to the latest version of supertokens-node (22.1.0) and saw that there is a tenant page inside the dashboard from Supernode. I might give someone access to this dashboard but without wishing to expose direct access to my database. See screenshot below.

This also means my database password is being transferred to my client which I feel is a security risk. I would have expected this data to be censored (and never leave the server where I run supertokens-node).

Image

Apart from that, this dashboard is very useful.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions