OAuth 'accessible-resources` endpoint doesn't validate scope against each product

XMLWordPrintable

    • Severity 3 - Minor

      accessible-resources API doesn't validate scopes per product instance and blindly trusts that the APP has a Grant for ALL instances of the same product. This isn't always true and some customer gets a list back with a product instance that the OAuth token doesn't have access to.

            Assignee:
            Grzegorz Zgudka
            Reporter:
            Nashid Farhad
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: