From: Jeremy Davis Date: Mon, 28 Sep 2015 14:10:05 +0000 (-0400) Subject: 37669 Additional back-office disclaimers X-Git-Url: http://git.freeside.biz/gitweb/?a=commitdiff_plain;h=ef9491e6007b7aed7ae0e0486a6abb237ca08519;p=freeside.git 37669 Additional back-office disclaimers --- diff --git a/FS/FS/API.pm b/FS/FS/API.pm index cc5f6092a..d331a9b6d 100644 --- a/FS/FS/API.pm +++ b/FS/FS/API.pm @@ -23,7 +23,9 @@ This module implements a backend API for advanced back-office integration. In contrast to the self-service API, which authenticates an end-user and offers functionality to that end user, the backend API performs a simple shared-secret authentication and offers full, administrator functionality, enabling -integration with other back-office systems. +integration with other back-office systems. Only ccess this API from a secure +network from other backoffice machines. DON'T use this API to create customer +portal functionality. If accessing this API remotely with XML-RPC or JSON-RPC, be careful to block the port by default, only allow access from back-office servers with the same