Authorizations of nested commands executed by user code

XMLWordPrintable

    • Type: Task
    • Resolution: Fixed
    • Priority: L3 - Default
    • 7.3.0, 7.3.0-alpha4
    • Affects Version/s: None
    • Component/s: engine
    • None

      At:

      • Constraints:
        Whenever the process engine invokes user code:
        1. the currently authenticated user is set on the thread (ie: if identityService.setAuthentication() was invoked from the same thread earlier, the authentication is still present
        2. If the user code executes nested commands, authorizations are not enforced.
      • the second constraint is configurable (can be switched on / off in configuration)

            Assignee:
            Daniel Meyer
            Reporter:
            Daniel Meyer
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: