Project

General

Profile

Actions

Bug #12720

closed

Technique Editor may ignores some error when authenticating, leading to unauthorized access

Added by Nicolas CHARLES almost 6 years ago. Updated almost 2 years ago.

Status:
Released
Priority:
N/A
Category:
Web - Technique editor
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Operational - other Techniques | Technique editor | Rudder settings
Effort required:
Priority:
0
Name check:
Fix check:
Regression:

Description

A user in read-only can change techniques in the Technique Editor
User with role read_only can still update techniques
Note that the Technique Editor button is not present in this case in the Directive Tree


Related issues 1 (0 open1 closed)

Related to Rudder - Bug #12747: apache overwrites error response from RudderReleasedBenoît PECCATTEActions
Actions

Also available in: Atom PDF