Lock down public Swagger UI docs
exposed-swagger
Public Swagger UI hands an attacker a working map of every endpoint, parameter and model. Serve it to authenticated staff or only in development.
Why this matters
Your API documentation is publicly accessible. It maps out endpoints and data models — reconnaissance data that aids attackers but is not directly exploitable.
Frameworks
Express
- 1 Restrict Swagger UI to development or add authentication
javascript
// Only enable Swagger in development
if (process.env.NODE_ENV !== 'production') {
app.use('/api-docs', swaggerUi.serve, swaggerUi.setup(spec));
}Does your app still have this?
Scan your domain