Require authentication to view Sierra API documentation
Enhance cybersecurity by not revealing the api methods through the swagger interface to unauthenticated users. For example, a potential hacker can view the swagger interface which shows all methods and explains how to use them. This is an issue on all api endpoints including the iii sandbox. My idea is to only reveal the swagger methods to authenticated users.
https://sandbox.iii.com/iii/sierra-api/swagger/index.html#!/patrons
In accordance with the Idea Graduation Workflow guidelines agreed upon by Innovative and IUG, this idea has been closed because it was submitted more than two years ago and has not been selected for inclusion in the product.
This idea is still available for commenting but is no longer eligible for voting.
Ideas that were submitted three or more years ago are archived for future reference.
-
Bob Gaydos
commented
Can one see the API endpoints in swagger without a valid API key and secret?
-
Greg Smith
commented
I have to agree. Even though it's slightly inconvenient and despite the fact that "security through obscurity" isn't a valid security control in and of itself, keeping the Sierra API documentation public could still make it easier to exploit any vulnerabilities that affect it.