Not logged users get LDAP password information from the 404 page #851

Closed
opened 2026-02-04 22:29:31 +03:00 by OVERLORD · 3 comments
Owner

Originally created by @Carlosongit on GitHub (Oct 8, 2018).

Describe the bug
When a non allowed user tries to access an article he gets a 404 page where all the config info can be seen.

Steps To Reproduce
Steps to reproduce the behavior:

  1. Share an article page to someone
  2. This someone is not logged to the Bookstack and click on the link
  3. He/she gets a 404 page with all the info from the server including the LDAP password
  4. See error

Expected behavior
A clear and concise description of what you expected to happen.

Screenshots
image
image

Your Configuration (please complete the following information):

  • Exact BookStack Version (Found in settings): BookStack v0.22.0
  • PHP Version: PHP 7.2.10-0ubuntu0.18.04.1 (cli) (built: Sep 13 2018 13:45:02) ( NTS )
  • Hosting Method (Nginx/Apache/Docker): Apache

Additional context
I would rather have a non logged user redirected to the login page.
And of course be sure that any important information is not shown.

Thank you in advance for this fabulous application and for any further help.

Carlos

Originally created by @Carlosongit on GitHub (Oct 8, 2018). **Describe the bug** When a non allowed user tries to access an article he gets a 404 page where all the config info can be seen. **Steps To Reproduce** Steps to reproduce the behavior: 1. Share an article page to someone 2. This someone is not logged to the Bookstack and click on the link 3. He/she gets a 404 page with all the info from the server including the LDAP password 4. See error **Expected behavior** A clear and concise description of what you expected to happen. **Screenshots** ![image](https://user-images.githubusercontent.com/43954188/46603125-73e3b780-caf2-11e8-9fe3-0271d5e6ca20.png) ![image](https://user-images.githubusercontent.com/43954188/46603192-a7bedd00-caf2-11e8-88b4-a8084e03a3fc.png) **Your Configuration (please complete the following information):** - Exact BookStack Version (Found in settings): BookStack v0.22.0 - PHP Version: PHP 7.2.10-0ubuntu0.18.04.1 (cli) (built: Sep 13 2018 13:45:02) ( NTS ) - Hosting Method (Nginx/Apache/Docker): Apache **Additional context** I would rather have a non logged user redirected to the login page. And of course be sure that any important information is not shown. Thank you in advance for this fabulous application and for any further help. Carlos
OVERLORD added the 📖 Docs Update Question labels 2026-02-04 22:29:31 +03:00
Author
Owner

@ssddanbrown commented on GitHub (Oct 11, 2018):

Hi @Carlosongit,
This is only showing since debug mode is turned on.

I'd advise you disable debug mode in normal operation to avoid such scenarios.

@ssddanbrown commented on GitHub (Oct 11, 2018): Hi @Carlosongit, This is only showing since debug mode is turned on. I'd advise you disable debug mode in normal operation to avoid such scenarios.
Author
Owner

@Carlosongit commented on GitHub (Oct 12, 2018):

Dan, it Was absolutely the answer thank you.

How can I close this ticket as resolved ?

Cheers,

Carlos Alonso Souza

Le 11 oct. 2018 à 09:41, Dan Brown notifications@github.com a écrit :

Hi @Carlosongit,
This is only showing since debug mode is turned on.

I'd advise you disable debug mode in normal operation to avoid such scenarios.


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub, or mute the thread.

@Carlosongit commented on GitHub (Oct 12, 2018): Dan, it Was absolutely the answer thank you. How can I close this ticket as resolved ? Cheers, Carlos Alonso Souza > Le 11 oct. 2018 à 09:41, Dan Brown <notifications@github.com> a écrit : > > Hi @Carlosongit, > This is only showing since debug mode is turned on. > > I'd advise you disable debug mode in normal operation to avoid such scenarios. > > — > You are receiving this because you were mentioned. > Reply to this email directly, view it on GitHub, or mute the thread.
Author
Owner

@ssddanbrown commented on GitHub (Oct 13, 2018):

Thanks @Carlosongit for confirming that solves this.
I've now added a warning to the debugging page in the BookStack docs to highlight this.

@ssddanbrown commented on GitHub (Oct 13, 2018): Thanks @Carlosongit for confirming that solves this. I've now added a warning to the debugging page in the BookStack docs to highlight this.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/BookStack#851