bcgov / bcgov/entity

Legal API: should respond 401 if wrong account is used to access data

Open
#24,647 2 comments 0 reactions 0 assignees View on GitHub
bug Entities Team Priority3 techdebt
Dominant language
JavaScript
Stars
23
Forks
62
Avg merge
24m
Merged PRs (30d)
1

Description

The legal API allows an account (eg, 668) to access business data from a different account (eg, 2288). This may be because both accounts as under the same login (BCREG0020).

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, endpoint, or entry points are named. Start by reproducing access with account 668 against account 2288 under the shared login BCREG0020, then trace the Legal API authorization path. Done means cross-account data access is rejected with HTTP 401 and the behavior is covered by an appropriate test.

Written by the indexing model from the issue text.

Assessment

Domain
api, authorization, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.