Enterprise templates are exposed if no authorised engine header is set

XMLWordPrintable

    • Type: Bug Report
    • Resolution: Won't Fix
    • Priority: L3 - Default
    • None
    • Affects Version/s: 7.8.13, 7.9.11, 7.10.5, 7.11.0-alpha4
    • Component/s: webapp
    • None

      Steps to reproduce
      Perform a GET request for an enterprise template without a http header for authorised engines (X-Authorized-Engine).

      Problem
      Enterprise templates are exposed if license is missing / invalid

      Reason
      When http header for authorised engines is not set, templates are exposed if license is missing

      Impact
      No impact – just strange.

      Hint
      See https://github.com/camunda/camunda-bpm-platform-ee/blob/master/webapps/camunda-webapp/plugins/src/main/java/org/camunda/bpm/webapp/impl/plugin/LicenseCheckResourceOverride.java#L84-L90

            Assignee:
            Thorben Lindhauer
            Reporter:
            Tassilo Weidner-Mühl
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: