Actions
Bug #8790
closedA read only account should not have access to API tokens
Status:
Released
Priority:
N/A
Assignee:
Category:
Web - Config management
Target version:
Pull Request:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
Operational - other Techniques | Technique editor | Rudder settings
Effort required:
Priority:
52
Name check:
Fix check:
Regression:
Description
At least until we heave read-only tokens.
A read_only user can read current tokens and modify them, and gets a full write access to the configuration.
Actions