Skip to main content
Announcements
Qlik Connect 2024! Seize endless possibilities! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
vegard_bakke
Partner - Creator III
Partner - Creator III

Dependencies on /api/about/ requests?

Does anyone know what is dependent on the /api/* requests, such as:

  • https://host/prefix/api/about/v1/components
  • https://host/prefix/api/about/v1/systeminfo
  • https://host/prefix/api/about/v1/language
  • https://host/prefix/api/v0/features
  • https://host/prefix/api/v1/csrf-token

I don't like  announcing the version numbers of neither Qlik Sense, its features nor any of its components.

 

The documentation, such as https://help.qlik.com/en-US/sense-developer/November2019/Subsystems/AboutServiceAPI/Content/Sense_Ab... does not say anything about its purpose, or what it is being used for.

 

What do I risk if I don't permit any /prefix/api/* calls through my reverse proxy?

 

Best regards,
Vegard

Labels (3)
1 Reply
ab9503
Contributor II
Contributor II

"I don't like  announcing..."
I completely agree. Security risk.

Any luck with this question? Thanks.