JMoran1 / DAESDgroup

2 stars 0 forks source link

Manually test to ensure that the Django Admin site cannot be used to bypass existing authorisation levels #146

Closed saxbophone closed 1 year ago

saxbophone commented 1 year ago

E.g. create an account of each Role type and then login with said account, go to /admin and make sure they do not have CRUD permissions for object types that are not within that role's permission-set