-
Notifications
You must be signed in to change notification settings - Fork 684
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update WP Best Practices to include guidance on blocking /wp-json/wp/v2/users
to anonymous users
#9167
Conversation
/wp-json/wp/v2/users
to anonymous users
⚡ Deployed with Pantheon Decoupled This build was successfully deployed with Pantheon. You can track the build logs here. 👀 Preview: https://pr-9167-documentation.appa.pantheon.site |
⚡ Deployed with Pantheon Decoupled This build was successfully deployed with Pantheon. You can track the build logs here. 👀 Preview: https://pr-9167-documentation.appa.pantheon.site |
⚡ Deployed with Pantheon Decoupled This build was successfully deployed with Pantheon. You can track the build logs here. 👀 Preview: https://pr-9167-documentation.appa.pantheon.site |
@jazzsequence I see we already have a similar example in this doc here: https://docs.pantheon.io/guides/wordpress-developer/wordpress-best-practices#disable-anonymous-access-to-wordpress-rest-api Is checking for access to the |
@rachelwhitton One is to disable the REST API entirely to anonymous users. The other only disables the |
@jazzsequence gotcha, that makes sense. I updated the headers for clarity. LGTM 👍 |
⚡ Deployed with Pantheon Decoupled This build was successfully deployed with Pantheon. You can track the build logs here. 👀 Preview: https://pr-9167-documentation.appa.pantheon.site |
⚡ Deployed with Pantheon Decoupled This build was successfully deployed with Pantheon. You can track the build logs here. 👀 Preview: https://pr-9167-documentation.appa.pantheon.site |
Fixes #8314
Summary
/users
endpoint for unauthenticated users./users
endpoint, and why you might want to do it, which links back to the above section in the Best Practices doc.