"localhost:8080?q=/rest/user" gives all user's names mails, pictures etc..
Isn't it a security problem? I don't want to share this information with everyone. How could I restrict the reachability of user info.

Comments

John_B’s picture

You could find out which module is providing data on this path and disable it. D6 does not natively provide REST data or any other data at this path.

Digit Professionals specialising in Drupal, WordPress & CiviCRM support for publishers in non-profit and related sectors