-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Any user can change an attribute of an object by creating a task #13735
Comments
@chirag-madlani let's close this for 1.2.3. |
…ent (open-metadata#14203) * fix: open-metadata#13735 task assignee should be entity owner if present * added e2e tests for the same * do not allow edit asignee in case of entity has owner
@harshach @chirag-madlani |
Hi, @AlekseevVadim Thanks for putting time into validating this. |
Affected module
UI and backend
Describe the bug
A user without the rights to edit an object can create a request to edit an attribute and, putting himself in the place of the assignee, make a change.
To Reproduce
Expected behavior
Object attributes can be changed as a result of task approval ONLY if the user who approved the change has the rights to edit the attribute.
Version:
Additional context
Prohibiting the change of the assignee when creating a task would be the wrong decision. Because if I set up the policies in such a way that the owner cannot change the description, he will be able to do this through task approval!!
The text was updated successfully, but these errors were encountered: