Details
-
Bug
-
Status: Closed
-
Resolution: Fixed
-
7.0.0 CE GA1, 7.0.1 CE GA2
-
6.2.x
-
Committed
-
1
-
4
-
Regression Bug
Description
Steps to reproduce:
- Sign in
- Get guest groupId (e.g. 20233)
- Get current p_auth token (e.g. 0fMsIhMD from page HTML source)
- Exchange groupId and p_auth token and hit: http://localhost:8080/api/jsonws/layout/update-layout/group-id/20233/private-layout/false/layout-id/1/type-settings/column-1=181%0alayout-template-id=2_columns_ii?p_auth=0fMsIhMD
- Display main page for guest group
Expected result: No exception in logs
Actual result: Exception stating that: Someone may be trying to circumvent the permission checker: {companyId=10155, name=118, primKey=118, scope=4}