[wp-trac] [WordPress Trac] #39806: Disable REST API by default, making it opt-in rather than always-on

WordPress Trac noreply at wordpress.org
Tue Feb 7 22:10:38 UTC 2017


#39806: Disable REST API by default, making it opt-in rather than always-on
-------------------------+------------------------------
 Reporter:  mor10        |       Owner:
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  Awaiting Review
Component:  REST API     |     Version:  trunk
 Severity:  normal       |  Resolution:
 Keywords:  close        |     Focuses:
-------------------------+------------------------------

Comment (by mor10):

 Replying to [comment:12 helen]:
 > Why should this be treated differently from XML-RPC? Have you gone
 through the history of the XML-RPC setting?

 The main concern voiced by people seems to be a) inbound data, and b) ease
 of use. Similar to XML-RPC, but with additional concerns added.

 This ticket was created in part to ask a recurring question not fully
 addressed about why the REST API is always-on by default. I'm not invested
 in disabling the feature myself, but enough conversations are happening
 that it needs to be addressed in a more public way. Making the case, as is
 being done in these responses, will quell at least some of these concerns.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/39806#comment:14>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list