CERT-Polska / mquery

YARA malware query accelerator (web frontend)
GNU Affero General Public License v3.0
413 stars 77 forks source link

Authentication behaviour is confusing #422

Closed msm-cert closed 3 weeks ago

msm-cert commented 3 weeks ago

When anonymous user has no roles assigned, this causes every user to have admin permissions (reported on discord).

Due to a bug in config editor, it's not possible to assign a nobody rule to the anonymous user, and the default permissions are admin permissions.