dotCMS / core

Headless/Hybrid Content Management System for Enterprises
http://dotcms.com
Other
863 stars 466 forks source link

Edit Content API: Whitelisting Content API Fields for Backend Users #30043

Closed fmontes closed 1 month ago

fmontes commented 1 month ago

User Story

Description: As a dotCMS administrator, I want to restrict the additional information fields (modUser, modUserName, owner, modDate) in the content API endpoint to be visible only for users with the backend user role, so that sensitive information is not exposed to unauthorized users.

Acceptance Criteria

Proposed Objective

"Core Features"

Proposed Priority

"Priority 3 - Average"

External Links

"N/A"

Assumptions & Initiation Needs

Quality Assurance Notes & Workarounds

fmontes commented 1 month ago

Dupe