erxes-api icon indicating copy to clipboard operation
erxes-api copied to clipboard

prevent leaking private data from configs to all users

Open sergeychikanov opened this issue 5 years ago • 1 comments

The general settings configs now contain fields that should not be exposed to all users in the system such as cloud credentials and mail server logins.

This uses the now-unused showGeneralSettings permissions to match the manageGeneralSettings permission set on config mutations so that data for users without the appropriate level isn't returned.

sergeychikanov avatar Apr 01 '20 18:04 sergeychikanov

Congratulations :tada:. DeepCode analyzed your code in 1.108 seconds and we found no issues. Enjoy a moment of no bugs :sunny:.

👉 View analysis in DeepCode’s Dashboard

ghost avatar Apr 01 '20 18:04 ghost