Skip to content

Conversation

@renetapopova
Copy link
Collaborator

Cherry-picked from #1440

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability to change your own privileges if you copy the admin role (otherwise the new role is essentially unconstrained).

…e their own privileges (neo4j#1440)

This was noticed in a recent internal pentest of RBAC.

We need to clarify that it is necessary to explicitly deny the ability
to change your own privileges if you copy the admin role (otherwise the
new role is essentially unconstrained).
@neo-technology-commit-status-publisher
Copy link
Collaborator

neo-technology-commit-status-publisher commented Feb 27, 2024

Thanks for the documentation updates.

The preview documentation has now been torn down - reopening this PR will republish it.

@renetapopova renetapopova merged commit 6eed543 into neo4j:5.x Feb 29, 2024
@renetapopova renetapopova deleted the 5.x-admin-privileges-clarification branch February 29, 2024 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants