Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WorkflowService - getEvents did not verify user read access #248

Closed
rsoika opened this issue Jan 25, 2017 · 1 comment
Closed

WorkflowService - getEvents did not verify user read access #248

rsoika opened this issue Jan 25, 2017 · 1 comment

Comments

@rsoika
Copy link
Member

rsoika commented Jan 25, 2017

The new implementation of workflowService EJB getEvents() did not verify the individual read access for events. So even if a event is read restricted, the method returns the event to the current user

@rsoika rsoika added this to the 4.0.6 milestone Jan 25, 2017
@rsoika
Copy link
Member Author

rsoika commented Jan 25, 2017

This bug need to be patched for version 3.9.x also

rsoika added a commit that referenced this issue Jan 25, 2017
issue #248
rsoika added a commit that referenced this issue Jan 25, 2017
@rsoika rsoika closed this as completed Jan 25, 2017
@rsoika rsoika added the testing label Jan 25, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant