Uploaded image for project: 'Atlas'
  1. Atlas
  2. ATLAS-2009

Any non-admin user in users-credentials.properties is able to access /api/atlas/admin path

Agile BoardAttach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • None
    • 0.8.1, 1.0.0
    • atlas-core
    • None

    Description

      Any non-admin user (ex: rangertagsync) specified in conf/users-credentials.properties is able to access the /api/atlas/admin path. Is this expected ?
      One of the use cases is Export and Import API's ,which should be permitted only by admin user to be executed. But any user is able to execute it.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            nixon Nixon Rodrigues
            sharmadhas Sharmadha S
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment