spring-projects / spring-projects/spring-data-rest
Field Security [DATAREST-1045]
@odrotbohm is already working on this.
Since Dec 31, 2020.
- Dominant language
- Java
- Stars
- 958
- Forks
- 568
- PR merge metrics
- No merged PRs in 30d
Description
benkuly opened DATAREST-1045 and commented
I think it should be possible to secure exported and imported fields in Spring Data Rest. Because Validator or EventHandler can't see if an user changed an field, it isn't possible to deny any change of it.
Example1: an user has an field "role", he easilly can change it to "ADMIN".
Example2: user A is not friend of user B. A should see "name" of B, but not the "email".
See reference URL for more information.
Reference URL: http://stackoverflow.com/questions/43157192/field-security-in-spring-data-rest
Issue Links:
- DATAREST-428 Field level security/visibility of exported resources
("duplicates")
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.