openkfw / TruBudget

A blockchain-based workflow tool for efficient and transparent project management
https://openkfw.github.io/trubudget-website/
GNU General Public License v3.0
83 stars 40 forks source link

User directory adapter: Login possible even though permissions/access was revoked #1855

Open ZuitAMB opened 1 month ago

ZuitAMB commented 1 month ago

How to reproduce 🕹

  1. Login using the user directory adapter
  2. Remove the permissions/access in the user directory
  3. Login again using the user directory adapter

Expected behavior: login is denied as the permission/access is missing Actual behavior: login is possible, as the browser uses cached responses from previous logins, which were successful Workaround: delete cookies/cache - but might not be suitable

Your Environment 🌎

Tech Version
Frontend v2.10.0
API v2.10.0
Blockchain v2.10.0
Provisioning v2.10.0
Export-Service N/A
Email-Service N/A
Storage-Service N/A
Authbuddy 1.1.0