fix(sec): protect transition route
All threads resolved!
All threads resolved!
Fix a security issue that allowed anybody to apply a transition to any profile.
- require user to be logged to apply a transition
- only profile own and admin can apply a transition
Fix #135 Ref !80 (merged)
Merge request reports
Activity
changed milestone to %0.1.0 (reboot)
added app / core priority / critical type / security 🔴 labels
requested review from @kaiyou
assigned to @f00wl
- Resolved by ornanovitch
added 1 commit
- 0d6663c4 - fix(sec): use predefined `authorized` function from actions.py
enabled an automatic merge when the pipeline for 28d25c24 succeeds
mentioned in commit f173cf0d
Please register or sign in to reply