Authorization list in dashboard doesn't filter by user/identity, DELETE endpoint lacks auth check #6

Closed
opened 2025-11-13 09:49:51 +00:00 by arne · 1 comment
Owner

I can see all authorizations on the server, not just the one for my user

2025-11-13_104802

2025-11-13_104810

This also means we don't correctly guard the DELETE endpoint, since I can delete all of these.

I can see all authorizations on the server, not just the one for my user ![2025-11-13_104802](/attachments/ea695409-216b-4e51-9666-9604be852ca2) ![2025-11-13_104810](/attachments/70c276b4-351c-4265-8aec-d315f73137e5) This also means we don't correctly guard the DELETE endpoint, since I can delete all of these.
laurence referenced this issue from a commit 2025-11-13 11:11:38 +00:00
Owner

fixed

fixed
Sign in to join this conversation.
No labels
bug
small
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gaiwan/Oak#6
No description provided.