diff --git a/searx/webapp.py b/searx/webapp.py index 151eb5cc6..b7ff2e101 100755 --- a/searx/webapp.py +++ b/searx/webapp.py @@ -1319,6 +1319,8 @@ def clear_cookies(): @app.route('/config') def config(): + if not get_setting('security.config_page'): + flask.abort(403) """Return configuration in JSON format.""" _engines = [] for name, engine in engines.items():