spring-projects / spring-projects/spring-data-rest

Field Security [DATAREST-1045]

Open
#1,411 4 comments 0 reactions 1 assignee View on GitHub

@odrotbohm is already working on this.

Since Dec 31, 2020.

type: enhancement
Dominant language
Java
Stars
958
Forks
568
PR merge metrics
No merged PRs in 30d

Description

benkuly opened DATAREST-1045 and commented

I think it should be possible to secure exported and imported fields in Spring Data Rest. Because Validator or EventHandler can't see if an user changed an field, it isn't possible to deny any change of it.

Example1: an user has an field "role", he easilly can change it to "ADMIN".

Example2: user A is not friend of user B. A should see "name" of B, but not the "email".

See reference URL for more information.


Reference URL: http://stackoverflow.com/questions/43157192/field-security-in-spring-data-rest

Issue Links:

  • DATAREST-428 Field level security/visibility of exported resources
    ("duplicates")

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.