-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
-
Server Security
-
ALL
-
Server Security 2025-08-29, Server Security 2025-09-12
-
None
-
None
-
None
-
None
-
None
-
None
-
None
If a command invokes another command internally (e.g. through DBDirectClient), the AuthorizationContract in the current AuthorizationSessionImpl will be reset when the SEP initiates the internal command, and the existing checks that were performed for the outer command will no longer be verified against the contract when the outer command finishes execution.