Description
If Grant/Revoke REST API is invoked by a user which is not a admin or not listed in policy.grantrevoke.auth.users config parameter value, then resource being granted permission to should not specify ownership information. Otherwise, such user may be able to modify a resource for which it does not have delegated-admin privilege.