Quantcast
Channel: Support & Bugs - Matomo forums
Viewing all articles
Browse latest Browse all 5981

Token_auth totally ignored with the http API calls! Serious issue

$
0
0

PHP 7.4 & latest version of on premise Matomo 4.x

Token Auth is not needed!
Invalid token auth is also accepted!

And the visits show up in both above cases on the dashboard, under Dashboart/ visits log !!!

Is this intended? If so, then this is flabbergasting. Anyone can flood my dashboard! And the URL isn’t hard to guess …they simply have to look at the javascript requests and figure out what’s the URL to matomo.php and flood my dashboard :frowning:

I can provide logs on request

1 post - 1 participant

Read full topic


Viewing all articles
Browse latest Browse all 5981

Trending Articles