Declined
1
[Feature Request] Secure Native Metrics Endpoint & Read-Only API Tokens (Follow-up to #1541)
Source: paperless-ngx/paperless-ngx#12186 · opened by @Xyz00777
Description Hi everyone, I'm writing this because the original discussion on this topic (#1541) was automatically closed, and I believe we need to revisit this from a "secure by design" perspective. The Core Problem: Token Permissions and Security I understand the argument that exporting data to Prometheus or similar monitoring stacks is generally the responsibility of a third-party tool. However, providing that base data securely should be a core Paperless responsibility. Currently, to get instance-wide metrics, you have to give a service user full Administration permissions. This is a major security risk. If that monitoring service or token is compromised, the attacker can see, edit, and delete all documents across the system. I don't even like creating a token on my own standard user account to check metrics, because currently, tokens mirror 100% of the user's permissions and can edit/delete documents. Proposed Solutions: To fix this and make…
No pledges yet. Be the first to back this.
Comments
Similar requests
[Feature Request] App Authentication Flow for Mobile/Desktop Apps (Login Flow v2)
6 votes · 0 comments
Add support for Ollama's think: false parameter for AI suggestions
1 vote · 0 comments
[Feature Request] Remove AI API key max length of 1024 characters
2 votes · 0 comments
[Feature Request] Add secure PDF redaction to the document editor
1 vote · 0 comments
[Feature Request] Allow configuring multiple LLM endpoints with priority and automatic failover.
1 vote · 0 comments
No comments yet.