Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing permissions on certain API endpoints #3740

Open
PascalRepond opened this issue Aug 29, 2024 · 0 comments
Open

Missing permissions on certain API endpoints #3740

PascalRepond opened this issue Aug 29, 2024 · 0 comments
Labels
correction An implemented feature doesn't work as expected.

Comments

@PascalRepond
Copy link
Contributor

How it works

Some simplified resources are missing permission settings on api endpoints.

Improvement suggestion

  • /api/import_bnf/?q=* and "import from the web" menu, should be restricted to logged users with full_permissions or cataloging_manager
  • /api/item/inventory?q=* should be restricted to any professionnal user
@PascalRepond PascalRepond added the correction An implemented feature doesn't work as expected. label Aug 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
correction An implemented feature doesn't work as expected.
Projects
Status: Product Backlog
Development

No branches or pull requests

1 participant