[
https://issues.jboss.org/browse/WFLY-1789?page=com.atlassian.jira.plugin....
]
Ladislav Thon commented on WFLY-1789:
-------------------------------------
I remember discussing this with Brian, but I see that the TODO is still in the code. So
I'm leaving this open and assigned to Brian.
RBAC: OperationContextImpl.readResourceForUpdate is missing an
authorize call
-----------------------------------------------------------------------------
Key: WFLY-1789
URL:
https://issues.jboss.org/browse/WFLY-1789
Project: WildFly
Issue Type: Feature Request
Components: Domain Management
Reporter: Ladislav Thon
Assignee: Brian Stansberry
[This issue was in fact found on 2013-07-09 and is being filled now only for tracking
purposes.]
During code inspection, I found one method in the {{OperationContextImpl}} class that is
IMHO missing an {{authorize}} call: {{readResourceForUpdate}}. Compare with
{{readModelForUpdate}}. See TODO in the code.
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see:
http://www.atlassian.com/software/jira