Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

advanced support for resource entity and entitytype check in subscriptions #12

Open
chicco785 opened this issue Jan 21, 2022 · 0 comments
Assignees
Labels
enhancement New feature or request
Milestone

Comments

@chicco785
Copy link
Contributor

Is your feature request related to a problem? Please describe.

Ideally, a user should be able to create / modify subscription only if the referred entity / entity_type in the body is accessible to him.

Describe the solution you'd like

Rules for subscription creation and update should check that referred entities / entities types / paths ect, are authorised to the user. Most probably, it would be good to have a "specific" acl for that e.g. acl:subscribe (or something similar, using a custom namespace to avoid "breaking" the spec).

Describe alternatives you've considered

N/A

Additional context

N/A

@chicco785 chicco785 added the enhancement New feature or request label Jan 21, 2022
@chicco785 chicco785 assigned chicco785, c0c0n3 and Cerfoglg and unassigned c0c0n3 Jan 21, 2022
@chicco785 chicco785 added this to the 0.4 milestone Feb 8, 2022
@chicco785 chicco785 modified the milestones: 0.4, 0.6 Jun 14, 2022
@chicco785 chicco785 modified the milestones: 0.6, 1.0 Jul 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants