ynput / ayon-backend

Server codebase with API access to AYON
Apache License 2.0
18 stars 14 forks source link

GraphQL: Normal users can list users from projects they are not assigned to #236

Closed martastain closed 3 weeks ago

martastain commented 3 weeks ago

Story

To reproduce

Steps to reproduce the behavior:

image

Expected behavior

User shouldn't be permitted to see users on other projects