Details
-
Bug
-
Status: Resolved
-
Critical
-
Resolution: Fixed
-
1.5.1
-
None
Description
RealTimeGet just ignores filter queries currently in Solr (see SOLR-8436) which is how document level security is implemented, so if you can guess the document ids, you can access them.
Since we probably don't want to wait for a solr version with SOLR-8436 to be released, we should come up with a temporary work around.
Attachments
Attachments
Issue Links
- links to