on 2018 Jun 04 10:17 AM
Few extensions created are unexpectedly behaving as web extensions.This is a possible security issue . We are only expecting ..storefront extension to be a web extension. Could you please give suggestions.
Request clarification before answering.
Just to clarify that you should not disable the ones that behave as web extensions because these ussually need to be ones. For example cockpits, backoffice and so on. What you should do instead is: Disable those extensions that are not needed for customers in localextensions.xm for each customer frontend node. Restrict access for all none frontend web extensions in the loadbalancer.
You can find all web roots in hac.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.