HomePhorge

Require application "Can Use" capability to call Conduit methods

Description

Require application "Can Use" capability to call Conduit methods

Summary: Ref T603. If you don't have access to an application, prevent execution of its (authenticated) methods.

Test Plan: Restricted Tokens to only admins, then tried to view/call Token methods as a non-admin.

Reviewers: btrahan

Reviewed By: btrahan

CC: aran

Maniphest Tasks: T603

Differential Revision: https://secure.phabricator.com/D7342

Details

Provenance
epriestleyAuthored on Oct 17 2013, 12:51 PM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP32dca4b553f8: Fix lightbox downloads for embeded images and a warning
Branches
Unknown
Tags
Unknown

Event Timeline