Skip to content

Remediate security vulnerability false positive #58

Description

@WillTDA

Description

Update API docs to state that public/unauthed GET access to mod download on unlisted status pages is not a security vulnerability. UUID gates it by design so the download link can still work.

Motivation

n/a

Alternatives Considered

n/a

Additional Context

Originally flagged by Claude Opus 5 as a security concern during testing, but is a non-issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions