Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-12765

REST API does not correctly handle authz for ADMIN in XSite, Query and Backups

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 12.1.0.Final
    • 12.0.1.Final
    • REST
    • None

      When the REST api performs operations on XSite, Query and Backups that can be only done for ADMIN users, admin user subject is not correctly handled and is detected as null, so REST endpoints respond with Subject null lacks ADMIN permission.

      Some uses like xsiteAdmin.checkSite(site) can't be used from the REST api without a wrapper that will check the subject in the request

              ttarrant@redhat.com Tristan Tarrant
              karestig@redhat.com Katia Aresti
              Archiver:
              rhn-support-adongare Amol Dongare

                Created:
                Updated:
                Resolved:
                Archived: