Skip to content

Conversation

@phil198
Copy link
Contributor

@phil198 phil198 commented Feb 26, 2024

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability to change your own privileges if you copy the admin role (otherwise the new role is essentially unconstrained).

Copy link
Collaborator

@renetapopova renetapopova left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, @phil198

@renetapopova renetapopova self-assigned this Feb 26, 2024
@neo-technology-commit-status-publisher
Copy link
Collaborator

neo-technology-commit-status-publisher commented Feb 26, 2024

Thanks for the documentation updates.

The preview documentation has now been torn down - reopening this PR will republish it.

Copy link
Contributor

@Hunterness Hunterness left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I know we assigned Lasse to this but looks good to me

@renetapopova
Copy link
Collaborator

@phil198, Which version should this go into, 5.18 or current?

@phil198
Copy link
Contributor Author

phil198 commented Feb 27, 2024

@phil198, Which version should this go into, 5.18 or current?

current please @renetapopova

@renetapopova renetapopova merged commit 244a284 into neo4j:dev Feb 27, 2024
@renetapopova renetapopova removed the 5.18 label Feb 27, 2024
renetapopova pushed a commit to renetapopova/docs-operations that referenced this pull request Feb 27, 2024
…e their own privileges (neo4j#1440)

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).
renetapopova pushed a commit to renetapopova/docs-operations that referenced this pull request Feb 27, 2024
…e their own privileges (neo4j#1440)

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).
renetapopova added a commit that referenced this pull request Feb 28, 2024
…e their own privileges (#1451)

Cherry-picked from #1440 

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).

Co-authored-by: Phil Wright <95368282+phil198@users.noreply.github.com>
renetapopova added a commit that referenced this pull request Feb 29, 2024
…e their own privileges (#1450)

Cherry-picked from #1440 

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).

Co-authored-by: Phil Wright <95368282+phil198@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants