sergehuber opened a new pull request, #875:
URL: https://github.com/apache/unomi/pull/875

   ## Summary
   - After a successful Karaf realm login, require an administrator role for 
GraphQL.
   - Honour `X-Unomi-Tenant-Id` only when the subject has authority over that 
tenant.
   - Reserve the system context for subjects that hold system access; refuse 
the request instead of falling back to it.
   
   Stacked on #870's sibling branch: base is 
`graphql-authorize-selected-operation`. Retarget to master once that PR merges.
   
   ## Test plan
   - [ ] `GraphQLServletSecurityValidatorTest` role and tenant cases
   - [ ] CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to