@f0x it seems like it would be way easier to just uh make a config abstraction that lets you enable and disable specific API endpoints and methods than making individual config decisions like this but what do I know
@jonny i guess? but we already have *two* config flags that are supposed to disallow public, unauthorized api access, so why does gargamel keep punching holes in them