Skip to content

fix(auth): add missing access checks to server_sync_status#79

Closed
MegaManSec wants to merge 1 commit intooperasoftware:masterfrom
MegaManSec:lol2
Closed

fix(auth): add missing access checks to server_sync_status#79
MegaManSec wants to merge 1 commit intooperasoftware:masterfrom
MegaManSec:lol2

Conversation

@MegaManSec
Copy link
Copy Markdown
Contributor

Require global, server, or account admin before returning sync status. Limit account list to authorized scope. Prevents info disclosure to any authenticated LDAP user.

Require global, server, or account admin before returning sync status.
Limit account list to authorized scope. Prevents info disclosure to
any authenticated LDAP user.
@MegaManSec MegaManSec closed this by deleting the head repository Mar 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant