-
Notifications
You must be signed in to change notification settings - Fork 31
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Anonymous access to test fails due to hooks #50
Comments
@johnaohara Any comments? |
I don't think that we would want an anon user to see the webhooks defined for a test and should be restricted as to who can view/edit the webhooks. I am assuming that the endpoint returns a Yes, sry looks like it was copied from AlertingService and I didn't finsh the impl. |
The other settings in the test are readable even by an anonymous user - if it's sensitive you can make the test 'protected' (readable only by authenticated users) or 'private' (viewable only by the owner). Do you want to make webhooks an exception from that policy? |
This was fixed in f316f44 |
Retrieving hooks for given test
Horreum/src/main/java/io/hyperfoil/tools/horreum/api/HookService.java
Lines 230 to 241 in 31b1071
ADMIN
role. Is that intended @johnaohara ? Alternatively, do we want a custom priviledge to set that?The current problem is that this opening test by anonymous user results in an error message being shown rather than hiding/graying out the webhooks section.
Btw. it seems that the code was copied from elsewhere but not fully finished (method name, else branch returning variables...)
The text was updated successfully, but these errors were encountered: