[wp-trac] [WordPress Trac] #39806: Disable REST API by default, making it opt-in rather than always-on

WordPress Trac noreply at wordpress.org
Fri Feb 10 03:23:22 UTC 2017


#39806: Disable REST API by default, making it opt-in rather than always-on
-------------------------+------------------------------
 Reporter:  mor10        |       Owner:
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  Awaiting Review
Component:  REST API     |     Version:  trunk
 Severity:  normal       |  Resolution:
 Keywords:  close        |     Focuses:
-------------------------+------------------------------

Comment (by pcarvalho):

 I believe REST API has a place within wp, and hopefully be useful in
 improving rewrites.

 With that said,
 what we have done, at server level, was to block and ban ips requesting
 wp-json in our servers.

 It has been a though week.


 Lastly, I'm puzzled why this endpoint isn't protected by default:

 - https://news.microsoft.com/wp-json/wp/v2/users ( random site from
 showcase gallery )

 Why make it easier than ever to get all the usernames?

 thanks for reading,
 p.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/39806#comment:16>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list