Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-13239

Make eval permission checking more granular

    XMLWordPrintableJSON

Details

    • Icon: Improvement Improvement
    • Resolution: Done
    • Icon: Major - P3 Major - P3
    • None
    • 2.6.0-rc1
    • Security
    • None

    Description

      Currently the eval command require all available permissions in order to run. It would be better to only require permissions for the actual operations that is performed by the enclosed script.

      This is currently prevented by the way we parse and execute Javascript so it is a non-trivial problem to solve.

      Attachments

        Activity

          People

            backlog-server-platform DO NOT USE - Backlog - Platform Team
            andreas.nilsson Andreas Nilsson
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: