콘텐츠로 건너뛰기
메뉴
커뮤니티에 참여하려면 회원 가입을 하시기 바랍니다.
신고된 질문입니다
3807 화면

This is a serious security concern, defining group access rights on menu items is not enough to restrict access to actions

How do you protect against this ? someone could just try action ids one by one until they find an existing action that gives him/her access to potentially private information.

I restricted access to a window action to a specific group, but I was still able to see it with a user that doesn't belong to that group.

Is this a bug? or am I missing something?

아바타
취소
관련 게시물 답글 화면 활동
1
10월 23
8611
0
3월 15
4001
1
3월 15
5341
0
3월 25
929
2
10월 24
1965