Skip to content

Conversation

@phorward
Copy link
Member

@phorward phorward commented Nov 6, 2025

Currently, any listFilter that returns None raises error 401, althought a user is authorized. This fix raises error 403 forbidden when an authenticated user is not allowed to proceed.

Belongs to #29

Currently, any listFilter that returns None raises error 401, althought a user is authorized.
This fix raises error 403 forbidden when an authenticated user is not allowed to proceed.
@phorward phorward added this to the ViUR-core v3.9 milestone Nov 6, 2025
@phorward phorward added bug(fix) Something isn't working or address a specific issue or vulnerability usability annoying labels Nov 6, 2025
@sveneberth
Copy link
Member

This solves partly #29. But it's more a hack than a solution. Can we generalize this and use in on ever permission check? It should be consistent in edit/move/etc.

@phorward phorward added the viur-meeting Issues to discuss in the next ViUR meeting label Nov 11, 2025
@phorward phorward removed the viur-meeting Issues to discuss in the next ViUR meeting label Dec 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

annoying bug(fix) Something isn't working or address a specific issue or vulnerability usability

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

2 participants