Skip to content

Permissions not respected #2194

@mkimberlin

Description

@mkimberlin

Describe the bug
Something broke permissions. They aren't being respected when calls are made to the controllers.

To Reproduce
Steps to reproduce the behavior:

  1. Remove any permission
  2. Attempt to perform a related capability
  3. Notice that it works regardless of the lack of permission

Expected behavior
I would expect unauthorized errors to be thrown

Screenshots
Case 1:
Screenshot 2024-04-16 at 12 08 06 PM

Case 2:
Screenshot 2024-04-16 at 12 09 52 PM
Screenshot 2024-04-16 at 12 09 39 PM

Case 3:
Screenshot 2024-04-16 at 12 19 15 PM
Screenshot 2024-04-16 at 12 10 56 PM

Additional context
This is currently happening in the development environment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingsecuritySecurity related issuesserver

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions