-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
How to proceed if RBAC prohibits viewing of a key? #96
Comments
From a UX perspective it makes sense to:
Cheers |
we talked about this already and looked at it from a security perspective: when you are not allowed to see something, you should not know that there is something 🤔 like it is in other products. |
@TwizzyDizzy many thanks for the comment. Arguments against showing presence of existing data without access:
Arguments for showing that there is a secret without access:
We had a look at other tools and we learned that most tools will not show any occurrence of non-accessible data. Please let us know if you see other reasons on why to show hidden data. |
No further comment. |
Should HDM show that access to the key is denied?
Should HDM show nothing?
The text was updated successfully, but these errors were encountered: