shinesolutions/aem-helloworld-publish-dispatcher

Disallow /dispatcher/invalidate.cache in publish-dispatcher default configuration

Closed this issue · 1 comments

For security reason, /dispatcher/invalidate.cache should be disallowed within publish-dispatcher configuration. https://helpx.adobe.com/experience-manager/dispatcher/using/security-checklist.html
It's then up to the user to deploy a publish-dispatcher (dispatcher.any) config that opens it up if they need to invalidate cache from the outside.

Done. Included in 0.10.2 .