Peripli / service-manager

Service Manager Core
Apache License 2.0
69 stars 28 forks source link

Secure OSB get instance/binding for tenants #479

Closed pankrator closed 4 years ago

pankrator commented 4 years ago

Pull Request Template

Motivation

If someone creates a tenant scoped platform, then he/she can access instances and bindings created in other tenants.

Approach

Attach the plugin for platform id check of instance to get instance/binding

Pull Request status

coveralls commented 4 years ago

Coverage Status

Coverage increased (+0.02%) to 86.851% when pulling 644b9ba6f70320a094369b47a387ce35b4301823 on osb_sec into b0e2ca6faf23fd95d8afbbe314cb7fef78d0be81 on master.