Actions
Issue #8018
closedviewsets that are not guarded by rbac allow any user known to the system
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Sprint:
Sprint 88
Quarter:
Description
As discussed on the mailinglist, it seems to be better to restrict access to all endpoints not explicitly guarded by rbac to users with the is_staff
flag, aka admins.
Actions
Restrict default permissions to admin users
fixes #8018 https://pulp.plan.io/issues/8018