Skip to content

add_routes: warn when the monitoring routes are mounted without dependencies #301

Description

@allen0099

Split from #298, which covers the breaking 0.4.0 change.

Problem

add_routes(app) mounts /cached-hits and /cached-records with no access control unless dependencies is passed, and shows content previews by default. See #298 for what that exposes. Today the only notice is a docstring sentence, so an app can ship the open routes without anyone noticing.

Proposal

  • Emit a UserWarning from add_routes() when dependencies is None. Name the parameter, and say that 0.4.0 will require it and turn previews off by default (add_routes: monitoring routes are unauthenticated and expose content previews by default #298).
  • Accept an explicit dependencies=[] as a deliberate opt-out that does not warn, so local and test setups can silence it without adding a guard.
  • Update the docs examples to pass a guard, and mention the warning in the changelog.

No behaviour change besides the warning.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestmonitoringadd_routes monitoring endpointssecuritySecurity vulnerability or hardening

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions