Skip to content

/api/authz/features/<:string>: contract says admin-only, backend allows anonymous access #385

Description

@MMilosz

Please describe your request
Features.md states that /api/authz/features/<:string> is "restricted to system administrators"[1], but any unauthenticated user can access it[2] as backend uses permitAll()[3]. It also describes return codes 401 Unauthorized & 403 Forbidden[4]

[1]

RestContract/features.md

Lines 19 to 22 in 54bcdf6

## Single Feature
**/api/authz/features/<:string>**
Provide detailed information about a specific feature. Access is restricted to system administrators. The JSON response document is as follow

[2]
https://sandbox.dspace.org/server/api/authz/features/canDownload

[3]
https://github.com/DSpace/DSpace/blob/f9fe9434c24305e811d79da6b121b96b974c7731/dspace-server-webapp/src/main/java/org/dspace/app/rest/repository/AuthorizationFeatureRestRepository.java#L51-L59

[4]

RestContract/features.md

Lines 42 to 43 in 54bcdf6

* 401 Unauthorized - if you are not authenticated
* 403 Forbidden - if you are not logged in with sufficient permissions. Only system administrators can access

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authorizationRelated to user authorization / permissionsbug

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions