Sybren A. Stüvel d0557445cd Fix privilege escalation leak
A PUT request on /api/user/{user-id} by the user themselves would allow
too much, and would allow self-granting of roles (including admin),
group membership (so join any arbitrary project) and pretend to be
service accounts.
2017-05-04 12:48:30 +02:00
..
2017-05-04 12:48:30 +02:00
2016-08-19 09:19:06 +02:00
2017-03-31 14:52:58 +02:00