Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-12765

REST API does not correctly handle authz for ADMIN in XSite, Query and Backups

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 12.1.0.Final
    • 12.0.1.Final
    • REST
    • None

      When the REST api performs operations on XSite, Query and Backups that can be only done for ADMIN users, admin user subject is not correctly handled and is detected as null, so REST endpoints respond with Subject null lacks ADMIN permission.

      Some uses like xsiteAdmin.checkSite(site) can't be used from the REST api without a wrapper that will check the subject in the request

            [ISPN-12765] REST API does not correctly handle authz for ADMIN in XSite, Query and Backups

            Reproduced provided in the PR

            Katia Aresti added a comment - Reproduced provided in the PR

              ttarrant@redhat.com Tristan Tarrant
              karestig@redhat.com Katia Aresti
              Archiver:
              rhn-support-adongare Amol Dongare

                Created:
                Updated:
                Resolved:
                Archived: