Skip to content

job: cross-tenant GET/PATCH/DELETE returns 403 — same class as #217 (secure-404) #221

@CryptoJones

Description

@CryptoJones

Problem

Same class as the nine prior secure-404 fixes (#173 / #187 / #191 / #195 / #199 / #203 / #209 / #213 / #217), now on the customer-cascade-scoped Job: jobCustId → Customer.custCompId. Scoped callers can enumerate jobId populations by status code.

Fix

Collapse both cases into 404. Cascade auth preserved.

Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions