flowable / flowable/flowable-engine
Per-group IDM "REST-API Access" privilege assignment seems to be broken
- Langage dominant
- Java
- Étoiles
- 9.5k
- Forks
- 2.9k
- Merge moyen
- 7 h 8 min
- PR mergées (30 j)
- 2
Description
Tried on 6.4.1.
Steps to reproduce:
1) Create a user with test_user_id
2) Create a group
3) Add user to that group
4) Assign privilege "Access the REST API" to that group
5) Make and IDM API call with test_user_id credentials. Tried it with GET http://localhost:8080/flowable-rest/idm-api/users/test_user_id
6) Error 403 Forbidden.
Assigning REST Access to test_user_id directly makes mentioned request work fine.
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Piste de recherche
Reproduisez le problème avec l’IDM REST API en suivant les six étapes indiquées, en comparant l’accès basé sur les groupes avec l’affectation directe pour GET /flowable-rest/idm-api/users/test_user_id. Suivez la vérification des privilèges pour l’utilisateur de test et son appartenance au groupe, puis confirmez que le privilège « Access the REST API » attribué au groupe autorise la requête sans renvoyer 403 Forbidden.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- java
- Domaine
- api, authorization
- Type d'issue
- Bug
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Activité
- À l'abandon
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 42/100