New controls for unauthenticated web endpoints
A new set of controls help you keep track of web endpoints that are exposed without authentication:
- The Apps and Endpoints pages can now be filtered by web authentication, and tags clearly mark authenticated versus unauthenticated resources.
- Two new audit log events,
app.expose_unauthenticated_urlandendpoint.create_unauthenticated, record when unauthenticated endpoints are deployed. - A new environment setting — with a workspace-wide default — blocks web functions, web servers, and endpoints from being deployed without proxy auth. Find it on the Environments settings page.