FeatureFuel
1

[Feature Request] Secure Native Metrics Endpoint & Read-Only API Tokens (Follow-up to #1541)

Source: paperless-ngx/paperless-ngx#12186 · opened by @Xyz00777
Description Hi everyone, I'm writing this because the original discussion on this topic (#1541) was automatically closed, and I believe we need to revisit this from a "secure by design" perspective. The Core Problem: Token Permissions and Security I understand the argument that exporting data to Prometheus or similar monitoring stacks is generally the responsibility of a third-party tool. However, providing that base data securely should be a core Paperless responsibility. Currently, to get instance-wide metrics, you have to give a service user full Administration permissions. This is a major security risk. If that monitoring service or token is compromised, the attacker can see, edit, and delete all documents across the system. I don't even like creating a token on my own standard user account to check metrics, because currently, tokens mirror 100% of the user's permissions and can edit/delete documents. Proposed Solutions: To fix this and make…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests