Skip to content

[GRDM-50105] Fix incorrect permission handling for file operations when using Personal Access Tokens #600

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 2 commits into
base: develop
Choose a base branch
from

Conversation

ndnhat1
Copy link

@ndnhat1 ndnhat1 commented Apr 28, 2025

Ticket

GRDM-50105

Purpose

Fix issue where users with read-only permission Personal Access Tokens could write files via the Waterbutler API

Changes

  • addons/base/views.py
    • Always verify permissions when the API uses a Personal Access Token.

QA Notes

Documentation

Side Effects

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants