Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-15316

Security issue with admin and grant/deny

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 15.0.0.Dev05
    • 15.0.0.Dev04
    • REST
    • None

      Role mapping and grant deny, does not check is a user exists, simply responds with "self". in the case of implicit roles and creating an admin user, if we grant observer role to admin mapping, we can't access the server anymore since admin is mapped to observer instead of admin. This can cause potential mistakes by not having access to an admin user anymore.

            karestig@redhat.com Katia Aresti
            karestig@redhat.com Katia Aresti
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: