Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Missing permissions on certain API endpoints #3740

@PascalRepond

Description

@PascalRepond

How it works

Some simplified resources are missing permission settings on api endpoints.

Improvement suggestion

  • /api/import_bnf/?q=* and "import from the web" menu, should be restricted to logged users with full_permissions or cataloging_manager
  • /api/item/inventory?q=* should be restricted to any professionnal user

Metadata

Metadata

Assignees

Labels

correctionAn implemented feature doesn't work as expected.

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions