Uploaded image for project: 'Causeway'
  1. Causeway
  2. CAUSEWAY-2719

with secman, Impersonation does not correctly figure out permissions of switched user

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • None
    • 2.0.0-M6
    • None
    • None

    Description

      Two separate (perhaps completely separate?) issues here:

      • for shiro.ini, we don't support "impersonateWithRoles", so my guess is that we keep the same roles as the original.
      • for secman, we ignore the roles specified using "impersonateWithRoles", because ApplicationUser#getPermissionSet joins across to the roles in the database, rather than the set of roles that are in the UserMemento.

       

      Attachments

        Activity

          People

            danhaywood Daniel Keir Haywood
            danhaywood Daniel Keir Haywood
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: