Details
-
Bug
-
Status: Resolved
-
Critical
-
Resolution: Fixed
-
2.3.0
Description
The RBAC changes attempt to perform authorization checks on resource-specific identifiers. This is not the intended use of the authorization (admin*/auth*) tables as the resource's adminresource id is to be looked up and an authorization check is to be performed on that.
Attachments
Attachments
Issue Links
- links to