Skip to content

Security: disable feature flag at client-side #4462

Closed Answered by daveleek
adisutanto asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @adisutanto!

What if the API response to client-side is intercepted and modified to feature disabled?
Would an attacker be able to disable an enabled feature?

Yes, but you should be using SSL for the traffic, also between Unleash and your internal services, along with allowing proper certificate chain validation. That's the typical way of dealing with potential MITM attacks

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by adisutanto
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants