eclipse-tractusx / managed-identity-wallet

Apache License 2.0
10 stars 23 forks source link

Avoid accidentally assigning `view|update_wallets` role due to human error #165

Open pablosec opened 12 months ago

pablosec commented 12 months ago

Finding from security assessment 23.12 (2023-11-21)

borisrizov-zf commented 8 months ago

@pablosec This issue is somewhat misplaced, as we don't control the assignment of roles. This should be coordinated with portal first. We can accommodate such a change after it has been deployed to portal.