Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

API should not return any user that has a "higher" role than them (manager shouldn't be able to see sys_admin) #43

Open
devincowan opened this issue Mar 16, 2023 · 2 comments
Assignees

Comments

@devincowan
Copy link
Collaborator

No description provided.

@ergjustin
Copy link
Contributor

Right now, the user's are able to view manager and sys-admin
email: [email protected]
password: WaterDendraFlow
image

@devincowan
Copy link
Collaborator Author

devincowan commented Apr 4, 2023

@jscottsf to add a filter to prevent this behavior
only see things at your level or below

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants