Resolve "ClientProtectedResourceMixin allows access if no allowed_scopes are set" #2656

Merged
Owner

Closes #688

Closes #688
Author
Owner

added 1 commit

  • a152704a - Reject access if there are no allowed_scopes set (ClientProtectedResourceMixin)

Compare with previous version

added 1 commit <ul><li>a152704a - Reject access if there are no allowed_scopes set (ClientProtectedResourceMixin)</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-Core/-/merge_requests/1011/diffs?diff_id=20649&start_sha=14262ec4fe0aea9d3f5440a434281c3d15bf9975)
Author
Owner

assigned to @nik

assigned to @nik
Author
Owner

marked this merge request as ready

marked this merge request as **ready**
Author
Owner

added 45m of time spent

added 45m of time spent
Owner
  allowed access if no scopes were allowed.
```suggestion:-0+0 allowed access if no scopes were allowed. ```
Owner

This needs a regression test.

This needs a regression test.
Author
Owner

added 1 commit

  • acf03a29 - Add regression test for broken ClientProtectedResourceMixin

Compare with previous version

added 1 commit <ul><li>acf03a29 - Add regression test for broken ClientProtectedResourceMixin</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-Core/-/merge_requests/1011/diffs?diff_id=20717&start_sha=a152704ac08abf18e2e1e0bb531b100728e5cae2)
Owner

This needs to be backported to 2.7

This needs to be backported to 2.7
Owner

Is there any good reason we are holding back this security fix, @hansegucker? What stops you from applying this suggestion?

Is there any good reason we are holding back this security fix, @hansegucker? What stops you from applying this suggestion?
Author
Owner

Not being on my laptop stopped me until now.

Not being on my laptop stopped me until now.
Author
Owner

resolved all threads

resolved all threads
Author
Owner

changed this line in version 3 of the diff

changed this line in [version 3 of the diff](/AlekSIS/official/AlekSIS-Core/-/merge_requests/1011/diffs?diff_id=20746&start_sha=acf03a29f1bc58820dbf5f62ed49255db81ca225#45267e3a9556cafa9cb7b61dab7a3b6659e73aad_30_30)
Author
Owner

added 1 commit

Compare with previous version

added 1 commit <ul><li>02669dca - Fix wording in changelog</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-Core/-/merge_requests/1011/diffs?diff_id=20746&start_sha=acf03a29f1bc58820dbf5f62ed49255db81ca225)
Owner

added 10 commits

  • 02669dca...edb64b64 - 9 commits from branch master
  • 480cf497 - Merge branch 'master' into...

Compare with previous version

added 10 commits <ul><li>02669dca...edb64b64 - 9 commits from branch <code>master</code></li><li>480cf497 - Merge branch &#39;master&#39; into...</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-Core/-/merge_requests/1011/diffs?diff_id=20889&start_sha=02669dca10341507782044971d3d7e7d5a984ca2)
nik scheduled this pull request to auto merge when all checks succeed 2022-05-03 23:58:53 +02:00
nik merged commit 0d39d5f566 into master 2022-05-04 00:53:00 +02:00
Owner

mentioned in commit 0d39d5f566

mentioned in commit 0d39d5f566e1d916e3c8dedd3f5bd62161f30bd8
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aleksis/AlekSIS-Core!2656
No description provided.