Skip to content

moved user can continue to call getReviewObjectByUUID #1774

@ElectricNroff

Description

@ElectricNroff

If a user had been in one organization, and happened to save the UUID of a ReviewObject document, but then is moved to a different organization (and has admin access there), then the user can leverage GET /review/byUUID/:uuid to see the current content of that ReviewObject document. For example, a former employee may be able to monitor ongoing negotiations between their former employer and the Secretariat. This occurs because access control does not check the relationship between the caller's organization and the target_object_uuid property.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions