-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Component/s: Directory - User Management REST API
-
Severity 3 - Minor
accessible-resources API doesn't validate scopes per product instance and blindly trusts that the APP has a Grant for ALL instances of the same product. This isn't always true and some customer gets a list back with a product instance that the OAuth token doesn't have access to.
- causes
-
ECOHELP-37772 Loading...
- is related to
-
METRO-1942 Loading...