Disallow /dispatcher/invalidate.cache in publish-dispatcher default configuration
Closed this issue · 1 comments
cliffano commented
For security reason, /dispatcher/invalidate.cache
should be disallowed within publish-dispatcher configuration. https://helpx.adobe.com/experience-manager/dispatcher/using/security-checklist.html
It's then up to the user to deploy a publish-dispatcher (dispatcher.any) config that opens it up if they need to invalidate cache from the outside.
cliffano commented
Done. Included in 0.10.2 .