Skip to content

Security : secret inventory security check is made on front side #1

@cyril-colin

Description

@cyril-colin

For now, it is the front application that check if current user is allowed to see an inventory.

We should not return the secret inventory from the backend if the connected user is not allowed (not the DM or not the owner)

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions