Skip to content

Consider if we have a security issue when specifying action without type #229

Description

@kjellmorten

Most actions will have payload.type, but if you specify a targetService you may not be required to. However, the authorization uses payload.type to check what auth schema to use, and no type means no authorization.

This should be addressed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions