Uploaded image for project: 'Causeway'
  1. Causeway
  2. CAUSEWAY-3740

[NOT A PROBLEM] Fix security perms to prevent users from adding themselves to a role just by guessing the role.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Not A Problem
    • 2.0.0
    • 2.1.0, 3.1.0
    • None
    • None

    Description

      While we currently do prevent users from adding a role to their ApplicationUser, we do not have a restriction to prevent a user from adding a user from an ApplicatoinRole.  So if they were to guess what a role is, this might be a backdoor.

      Attachments

        Activity

          People

            danhaywood Daniel Keir Haywood
            danhaywood Daniel Keir Haywood
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: