Anyone who could reach my FastAPI RAG service could query every document in it. The quick fix was a /login route: check the password against Postgres, sign a JWT, return it. It would have worked. But ask one question first: if someone stole this API's config and database, who could they become? With a signing secret in the config, the answer is... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
My RAG API Never Signs Tokens or Sees Passwords
Anyone who could reach my FastAPI RAG service could query every document in it. The quick fix was a /login route: check the password against Postgres, sign a…