Overslaan naar inhoud
Menu
Je moet geregistreerd zijn om te kunnen communiceren met de community.
Deze vraag is gerapporteerd
3615 Weergaven

This is a serious security concern, defining group access rights on menu items is not enough to restrict access to actions

How do you protect against this ? someone could just try action ids one by one until they find an existing action that gives him/her access to potentially private information.

I restricted access to a window action to a specific group, but I was still able to see it with a user that doesn't belong to that group.

Is this a bug? or am I missing something?

Avatar
Annuleer
Gerelateerde posts Antwoorden Weergaven Activiteit
1
okt. 23
8376
0
mrt. 15
3810
1
mrt. 15
5000
0
mrt. 25
756
2
okt. 24
1673