Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-5827

AuthorizationService#isAuthorized() performs an authorization check even when authorization is disabled

    XMLWordPrintable

    Details

      Description

      Steps to reproduce:
      1) configure a process engine whereby the property authorizationEnabled is set to false
      2) execute AuthorizationService#isAuthorized()

      Problem:
      AuthorizationService#isAuthorized() executes the authorization check. So that false is returned.

      Expected behavior:

      • AuthorizationService#isAuthorized() returns true, if the authorization is disabled.
      • No authorization check is performed

      Hints:
      In Admin the tabs Authorization and System are not be visible if the authorization is disabled.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              roman.smirnov Roman Smirnov
              Reporter:
              roman.smirnov Roman Smirnov
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: