-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ACL Allows Relation access even though DENY * #115
Comments
@superkhau could you help us here and check if strongloop/loopback-example-access-control#2 can be still reproduced in loopback 2.x? |
@bajtos it is reproducible. say we have two models,
|
What is your ACL? |
|
I have just bumped into this issue and it is a major roadblock for us to get our server into production. I tried to track down the problem and would greatly appreciate your help. All I can say is that the |
I don't think this is correct. Or to be specific I don't think you are attaching your
This calls the A potential issue (depending on how you expect ACL to work) is that the set of |
I'm closing this as its no longer an issue. Improvements will come to relation access control. Keep an eye on #1362 |
@raymondfeng
See strongloop/loopback-example-access-control#2 (comment)
For a reproducible case.
Connect to #1362
The text was updated successfully, but these errors were encountered: