Skip to content

productentry: cross-tenant GET/PATCH/DELETE returns 403 — same class as #213 (secure-404) #217

@CryptoJones

Description

@CryptoJones

Problem

Same class as the eight prior secure-404 fixes (#173 / #187 / #191 / #195 / #199 / #203 / #209 / #213), now on the job-cascade-scoped ProductEntry: pentJobId → Job.jobCustId → Customer.custCompId. Scoped callers can enumerate pentId populations by status code.

Fix

Collapse both cases into 404. Cascade auth resolution preserved.

Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions