Project

General

Profile

Actions

Bug #12440

closed

When the api authorization plugin is disabled tokens become read only

Added by Benoît PECCATTE over 6 years ago. Updated almost 5 years ago.

Status:
Released
Priority:
N/A
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Infrequent - complex configurations | third party integrations
Effort required:
Very Small
Priority:
78
Name check:
Fix check:
Regression:

Description

This could be a security problem if the token had restricted read rights, the token then have full access.
The token could instead be interpreted as disabled.


Related issues 1 (0 open1 closed)

Related to Rudder - User story #12111: Make fine-grained API authorization a pluginReleasedFrançois ARMANDActions
Actions

Also available in: Atom PDF