From 176fbed7c7a3dc5e3dab7b4ccb86f894b2b9117d Mon Sep 17 00:00:00 2001 From: Anthony Lukach Date: Wed, 30 Sep 2026 08:52:10 -0700 Subject: [PATCH] docs: warn that endpoints outside the filter paths are unfiltered Aggregation, collection search, and queryables endpoints are not covered by the default ITEMS_FILTER_PATH / COLLECTIONS_FILTER_PATH. Co-Authored-By: Claude Opus 5.5 --- docs/user-guide/configuration.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/user-guide/configuration.md b/docs/user-guide/configuration.md index fc6da1e3..af920ca2 100644 --- a/docs/user-guide/configuration.md +++ b/docs/user-guide/configuration.md @@ -329,6 +329,9 @@ These settings configure the CORS behavior when `PROXY_OPTIONS` is `false` (the - **Required:** No, defaults to `^(/collections/([^/]+)/items(/[^/]+)?$|/search$)` - **Example:** `^(/collections/([^/]+)/items(/[^/]+)?$|/search$|/custom$)` + > [!WARNING] + > Requests to paths matched by neither `ITEMS_FILTER_PATH` nor `COLLECTIONS_FILTER_PATH` are proxied **unfiltered**. If your upstream exposes other endpoints that reveal records or statistics about them, such as aggregation (`/aggregate`, `/collections/{id}/aggregate`), collection search (e.g. `/collections-search`), or queryables (`/queryables`, `/collections/{id}/queryables`), extend these patterns to cover them or block those endpoints. + ### `COLLECTIONS_FILTER_CLS` : CQL2 expression factor for collection-level filtering