Liferay provides many headless api’s. These are generally fairly useful to use in client extensions; however they seem to expose a lot of info about users within the portal, e.g. who created an object entry (including userId); things that could provide a hacker a target to attack.
Is there a mechanism to restrict what the headless api outputs regarding things like author info and such?
We currently are making our own rest services to wrap the normal liferay services instead so we can control what to return to the browser