Skip to content

[6.x] Replicator fieldtype endpoint hardening#14255

Merged
jasonvarga merged 1 commit into6.xfrom
replicator-set-endpoint
Mar 13, 2026
Merged

[6.x] Replicator fieldtype endpoint hardening#14255
jasonvarga merged 1 commit into6.xfrom
replicator-set-endpoint

Conversation

@jasonvarga
Copy link
Copy Markdown
Member

This PR ensures that the endpoint for getting replicator set metadata doesn't return information for blueprints that you don't have access to.

The endpoint accepted the fully-qualified blueprint handle to look up the field from the respective blueprint. This PR encrypts/decrypts it so you can't just request any blueprint.

@jasonvarga jasonvarga merged commit 60add14 into 6.x Mar 13, 2026
18 checks passed
@jasonvarga jasonvarga deleted the replicator-set-endpoint branch March 13, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant