Project

General

Profile

Actions

Bug #9747

closed

In 4.0.0, whole api is available under /secure/api, whatever the user role

Added by François ARMAND over 7 years ago. Updated almost 5 years ago.

Status:
Released
Priority:
1
Category:
API
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
Fix check:
Regression:

Description

In 4.0.0, we added access to the API under /secure path so that user can use it to configure settings.
But we added the whole API tree, and that, whatever the role.
We need to limit to only admin role (read => get / write => other verbs) the access to only the settings API.

Actions #1

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Vincent MEMBRÉ to François ARMAND
  • Pull Request set to https://github.com/Normation/rudder/pull/1394
Actions #2

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from Pending technical review to Pending release
  • % Done changed from 0 to 100
Actions #3

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 4.0.1 which was released today.

Actions #4

Updated by Vincent MEMBRÉ almost 5 years ago

  • Private changed from Yes to No
  • Priority set to 0
Actions

Also available in: Atom PDF