Project

Profile

Help

Issue #8524

Disable guardians' AnonymousUser

Added by ipanova@redhat.com 4 months ago. Updated 2 months ago.

Status:
CLOSED - CURRENTRELEASE
Priority:
Normal
Category:
-
Sprint/Milestone:
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Sprint:
Sprint 94
Quarter:

Description

The Guardian anonymous user is different from the Django Anonymous user. https://django-guardian.readthedocs.io/en/stable/configuration.html#anonymous-user-name

We are using DRF access policy which evaluetes this user as not anonymous and authenticated, this is a security concern. https://github.com/rsinger86/drf-access-policy/blob/master/rest_access_policy/access_policy.py#L99-L106

Associated revisions

Revision 5d63fc9a View on GitHub
Added by ipanova@redhat.com 4 months ago

Disable django guardian's anonymous user.

closes #8524

Required PR: https://github.com/pulp/pulp-cli/pull/198

History

#1 Updated by pulpbot 4 months ago

  • Status changed from NEW to POST

#2 Updated by ipanova@redhat.com 4 months ago

  • Assignee set to ipanova@redhat.com
  • Sprint set to Sprint 94

#3 Updated by fao89 4 months ago

  • Triaged changed from No to Yes

#4 Updated by ipanova@redhat.com 4 months ago

  • Status changed from POST to MODIFIED

#5 Updated by dalley 2 months ago

  • Sprint/Milestone set to 3.13.0

#6 Updated by pulpbot 2 months ago

  • Status changed from MODIFIED to CLOSED - CURRENTRELEASE

Please register to edit this issue

Also available in: Atom PDF