Actions
Issue #8018
closedviewsets that are not guarded by rbac allow any user known to the system
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Sprint:
Sprint 88
Quarter:
Description
As discussed on the mailinglist, it seems to be better to restrict access to all endpoints not explicitly guarded by rbac to users with the is_staff
flag, aka admins.
Updated by pulpbot almost 4 years ago
- Status changed from ASSIGNED to POST
Updated by dkliban@redhat.com almost 4 years ago
- Triaged changed from No to Yes
- Sprint set to Sprint 88
Added by mdellweg almost 4 years ago
Updated by mdellweg almost 4 years ago
- Status changed from POST to MODIFIED
Applied in changeset pulpcore|6e8f2c9377095fb01a069858daa37c5217fbbdf8.
Updated by pulpbot almost 4 years ago
- Status changed from MODIFIED to CLOSED - CURRENTRELEASE
Actions
Restrict default permissions to admin users
fixes #8018 https://pulp.plan.io/issues/8018