Skip to content

timeentry: cross-tenant GET/PATCH/DELETE returns 403 — same class as #233 (secure-404) #237

@CryptoJones

Description

@CryptoJones

Same class as the 13 prior secure-404 fixes, now on direct-company-scoped TimeEntry (teCompId). Collapse 403 "exists but not yours" into 404. Completes the secure-404 series for single-resource domain entities (VersionInfo + Customer have different shapes).

Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions