Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-3511

Permission checks don't take superuser session flag into account

    XMLWordPrintable

Details

    Description

      Some of our admin functions call code which performs permission checks. These permission checks don't do what we want, as we may be anonymous or logged in as a non-admin user, and so not have permission to perform actions.

      For instance, you can't add application links to a project unless you are logged in. See screenshot.

      We could fix this by adding 'isSuperuser' method to our Principal interface.

      Attachments

        Activity

          People

            Unassigned Unassigned
            tom@atlassian.com Tom Davies
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: