New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resources API should only list resources which the client has access to #522

Closed
jean-luc opened this Issue Dec 5, 2018 · 0 comments

Comments

Projects
None yet
2 participants
@jean-luc
Copy link
Member

jean-luc commented Dec 5, 2018

When querying the Resources API via /api/resources with any client bearer token

Expected behavior

I expect to see a list showing only collections and custom endpoints which the current client has access to.

Actual behavior

All collections and custom endpoints are listed, regardless of access permissions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment