All fixes

Restrict access to Laravel Telescope

tech-laravel-telescope

Telescope records real requests, queries and session payloads, and right now anyone can read them. Gate it behind an admin check or disable it.

Why this matters

Laravel Telescope is accessible without authentication. It exposes user requests, queries, and application state — more than reconnaissance since it contains actual user data, but requires specific conditions to extract sensitive information.

Laravel

  1. 1 Restrict Telescope to authorized users via TelescopeServiceProvider
  2. 2 Or remove Telescope from production entirely
php
// In app/Providers/TelescopeServiceProvider.php
protected function gate()
{
    Gate::define('viewTelescope', function ($user) {
        return in_array($user->email, [
            '[email protected]',
        ]);
    });
}
Laravel docs

Does your app still have this?

Scan your domain