All fixes

Lock down public Swagger UI docs

exposed-swagger

Public Swagger UI hands an attacker a working map of every endpoint, parameter and model. Serve it to authenticated staff or only in development.

Why this matters

Your API documentation is publicly accessible. It maps out endpoints and data models — reconnaissance data that aids attackers but is not directly exploitable.

Express

  1. 1 Restrict Swagger UI to development or add authentication
javascript
// Only enable Swagger in development
if (process.env.NODE_ENV !== 'production') {
  app.use('/api-docs', swaggerUi.serve, swaggerUi.setup(spec));
}

Does your app still have this?

Scan your domain