Skip to content

Rest api: /V1/store/websites is reachable without a valid customer key/secret #3719

@spotlerbob

Description

@spotlerbob

Steps to reproduce

  1. Install Magento from develop branch.
  2. Do a call to the /rest/V1/store/websites with a non empty Consumer key, Consumer key secret, Access token and Access token secret

Expected result

  1. 401 status code

Actual result

  1. Get a 200 status code and the list of available websites

Metadata

Metadata

Assignees

Labels

Issue: Ready for WorkGate 4. Acknowledged. Issue is added to backlog and ready for developmentbug report

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions