Configuration should require authentication.


Everyone can modify the settings of the application now. It would be better if the settings could only be modified when accessed from localhost, or best, by authentication.


r1964 introduces a fix where the TFS Project Info task now comes with with two configuration fields for setting the field name one wants to extract estimated effort and remaining effort from. These fields are pre-filled with Scrum for TFS v3 values, but can be changed when configuring the task.

I believe this is a good approach as we allow for any self created setup the users might have including other third party templates we have not cosidered.

Does anyone else have any input on this?

