From 4c8c839f65491c9ec41e78fce02ab5c91a5f4595 Mon Sep 17 00:00:00 2001 From: Jeremy Davis Date: Mon, 28 Sep 2015 10:08:02 -0400 Subject: [PATCH] 37669 Additional back-office disclaimers --- FS/FS/API.pm | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/FS/FS/API.pm b/FS/FS/API.pm index f848361ac..7ee080257 100644 --- a/FS/FS/API.pm +++ b/FS/FS/API.pm @@ -24,7 +24,9 @@ This module implements a backend API for advanced back-office integration. In contrast to the self-service API, which authenticates an end-user and offers functionality to that end user, the backend API performs a simple shared-secret authentication and offers full, administrator functionality, enabling -integration with other back-office systems. +integration with other back-office systems. Only ccess this API from a secure +network from other backoffice machines. DON'T use this API to create customer +portal functionality. If accessing this API remotely with XML-RPC or JSON-RPC, be careful to block the port by default, only allow access from back-office servers with the same -- 2.11.0