Finding from security assessment 23.12 (2023-11-21)
Likelihood for human error in accidentally assigning a role with much higher rights (view_wallets, update_wallets) is high, when the roles are only differentiated by a single letter s.
Some measure to avoid accidentally assigning the *_wallets to a user should be implemented, e.g., by renaming either the _wallet variant or the _wallets variant. Other counter-measure
@pablosec This issue is somewhat misplaced, as we don't control the assignment of roles. This should be coordinated with portal first. We can accommodate such a change after it has been deployed to portal.
Finding from security assessment 23.12 (2023-11-21)
view_wallets
,update_wallets
) is high, when the roles are only differentiated by a single letters
.*_wallets
to a user should be implemented, e.g., by renaming either the_wallet
variant or the_wallets
variant. Other counter-measure