| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
No evidence that Spring Actuators are being used, e.g. `http.authorizeRequests().anyRequest().permitAll()`
Only safe Actuators are enabled, e.g. `EndpointRequest.to("health", "info")`
| Back | FazBrowse Home | New Git URL |
This PR fixes FPs in SpringBootActuators query, as pointed out in #2901 (comment).
--> The query now makes sure that the permitAll() refers to Spring Actuators (EndpointRequest)
--> The query now raises the flag only if EndpointRequest.toAnyEndpoint() is being used.
More tests to handle the above cases are added.