No authorization checks when creating/saving/reading task attachments

XMLWordPrintable

    • Type: Bug Report
    • Resolution: Unresolved
    • Priority: L3 - Default
    • None
    • Affects Version/s: 7.3.0, 7.4.0
    • Component/s: engine
    • None

      Authorization checks should be performed based on the related task resource.

      Note that attachments are stored in the history tables and therefore not coupled to the lifetime of the runtime task entity.

      Forum post: https://groups.google.com/forum/#!topic/camunda-bpm-users/WWQyHusFZ9k

            Assignee:
            Unassigned
            Reporter:
            Thorben Lindhauer
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: