Skip to content

Commit

Permalink
docs(request-debug): add special note for loopback debug requests not…
Browse files Browse the repository at this point in the history
… requiring token (#13697)

Add a special note for `kong.conf.default` to mention that request debug is not authenticated with X-Request-Debug-Token when requests are originating from loopback.

KAG-5418
  • Loading branch information
Oyami-Srk authored Oct 9, 2024
1 parent 98e4291 commit 3a3b6ac
Showing 1 changed file with 5 additions and 2 deletions.
7 changes: 5 additions & 2 deletions kong.conf.default
Original file line number Diff line number Diff line change
Expand Up @@ -2264,8 +2264,11 @@
#
# - `X-Kong-Request-Debug-Token`:
# Token for authenticating the client making the debug
# request to prevent abuse. Debug requests originating from loopback
# addresses do not require this header.
# request to prevent abuse.
# ** Note: Debug requests originating from loopback
# addresses do not require this header. Deploying Kong behind
# other proxies may result in exposing the debug interface to
# the public.**
#
#request_debug_token = <random> # The Request Debug Token is used in the
# `X-Kong-Request-Debug-Token` header to prevent abuse.
Expand Down

1 comment on commit 3a3b6ac

@github-actions
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bazel Build

Docker image available kong/kong:3a3b6ac137a5588d141c086f82e19a690ebb71a0
Artifacts available https://github.com/Kong/kong/actions/runs/11250132954

Please sign in to comment.