AACEngineering / django-permissions-auditor

Tool to audit access control on your django app.
https://django-permissions-auditor.readthedocs.io/en/latest/
MIT License
20 stars 4 forks source link

django.contrib.admin.options #9

Open jayvdb opened 3 years ago

jayvdb commented 3 years ago

I have a lot list of views grouped under "django.contrib.admin.options" and all with "login required" = false, which does not appear logical. This is with Django 2.2

changelist_view | /admin/admin_interface/theme/ |   |   |  
add_view | /admin/admin_interface/theme/add/ |   |   |  
autocomplete_view | /admin/admin_interface/theme/autocomplete/ |   |   |  
history_view | /admin/admin_interface/theme/<path:object_id>/history/ |   |   |  
delete_view | /admin/admin_interface/theme/<path:object_id>/delete/ |   |   |  
change_view | /admin/admin_interface/theme/<path:object_id>/change/ |   |   |  
changelist_view | /admin/advanced_filters/advancedfilter/ |   |   |  
add_view | /admin/advanced_filters/advancedfilter/add/ |   |   |  
autocomplete_view | /admin/advanced_filters/advancedfilter/autocomplete/ |   |   |  
history_view | /admin/advanced_filters/advancedfilter/<path:object_id>/history/ |   |   |  
delete_view | /admin/advanced_filters/advancedfilter/<path:object_id>/delete/ |   |   |  
changelist_view | /admin/siteprefs/preference/ |   |   |  
add_view | /admin/siteprefs/preference/add/ |   |   |  
autocomplete_view | /admin/siteprefs/preference/autocomplete/ |   |   |  
history_view | /admin/siteprefs/preference/<path:object_id>/history/ |   |   |  
delete_view | /admin/siteprefs/preference/<path:object_id>/delete/ |   |   |  
change_view | /admin/siteprefs/preference/<path:object_id>/change/ |   |   |  
changelist_view | /admin/qsessions/session/ |   |   |  
add_view | /admin/qsessions/session/add/ |   |   |  
autocomplete_view | /admin/qsessions/session/autocomplete/ |   |   |  
history_view | /admin/qsessions/session/<path:object_id>/history/ |   |   |  
delete_view | /admin/qsessions/session/<path:object_id>/delete/ |   |   |  
change_view | /admin/qsessions/session/<path:object_id>/change/ |   |   |  
changelist_view | /admin/authtoken/tokenproxy/ |   |   |  
add_view | /admin/authtoken/tokenproxy/add/ |   |   |  
autocomplete_view | /admin/authtoken/tokenproxy/autocomplete/ |   |   |  
history_view | /admin/authtoken/tokenproxy/<path:object_id>/history/ |   |   |  
delete_view | /admin/authtoken/tokenproxy/<path:object_id>/delete/ |   |   |  
change_view | /admin/authtoken/tokenproxy/<path:object_id>/change/ |   |   |  
changelist_view | /admin/blacklist/blacklistedtoken/ |   |   |  
add_view | /admin/blacklist/blacklistedtoken/add/ |   |   |  
autocomplete_view | /admin/blacklist/blacklistedtoken/autocomplete/ |   |   |  
history_view | /admin/blacklist/blacklistedtoken/<path:object_id>/history/ |   |   |  
delete_view | /admin/blacklist/blacklistedtoken/<path:object_id>/delete/ |   |   |  
change_view | /admin/blacklist/blacklistedtoken/<path:object_id>/change/ |   |   |  
changelist_view | /admin/sites/site/ |   |   |  
add_view | /admin/sites/site/add/ |   |   |  
autocomplete_view | /admin/sites/site/autocomplete/ |   |   |  
history_view | /admin/sites/site/<path:object_id>/history/ |   |   |  
delete_view | /admin/sites/site/<path:object_id>/delete/ |   |   |  
change_view | /admin/sites/site/<path:object_id>/change/ |   |   |  
...