Skip to content

purchaseordervendor: cross-tenant GET/PATCH/DELETE returns 403 — same class as #195 (secure-404) #199

@CryptoJones

Description

@CryptoJones

Problem

Same class as #173/#187/#191/#195 on PurchaseOrderVendor. /v1/purchaseordervendor/:id GET/PATCH/DELETE returns 404 for absent ids but 403 for existing-but-not-yours, letting a scoped caller enumerate povId populations.

Fix

Collapse both cases into 404. Master + own-tenant paths unchanged.

Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions