Skip to content

Comments

fix(auth): add missing access checks to server_sync_status#79

Open
MegaManSec wants to merge 1 commit intooperasoftware:masterfrom
MegaManSec:lol2
Open

fix(auth): add missing access checks to server_sync_status#79
MegaManSec wants to merge 1 commit intooperasoftware:masterfrom
MegaManSec:lol2

Conversation

@MegaManSec
Copy link
Contributor

Require global, server, or account admin before returning sync status. Limit account list to authorized scope. Prevents info disclosure to any authenticated LDAP user.

Require global, server, or account admin before returning sync status.
Limit account list to authorized scope. Prevents info disclosure to
any authenticated LDAP user.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant