Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Messaging Service Connection can be accessed via API for Without Access #19596

Open
Prajwal214 opened this issue Jan 29, 2025 · 0 comments
Open
Assignees
Labels
backend bug Something isn't working customer

Comments

@Prajwal214
Copy link
Contributor

Affected module
Does it impact the UI, backend or Ingestion Framework?
-- Backend

Describe the bug
A clear and concise description of what the bug is.
-- A user with only the "Data Consumer" role cannot access the service connection via the UI - expected behavior.
• However, when the same user fetches service details via the API (e.g., for Kafka), the service connection, including credentials, is exposed - unexpected behavior

/v1/services/messagingServices/name/{name}

To Reproduce

Screenshots or steps to reproduce

Expected behavior
A clear and concise description of what you expected to happen.

Version:

  • OS: [e.g. iOS]
  • Python version:
  • OpenMetadata version: [e.g. 0.8]
  • OpenMetadata Ingestion package version: [e.g. openmetadata-ingestion[docker]==XYZ]

Additional context
Add any other context about the problem here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backend bug Something isn't working customer
Projects
Status: Platform
Development

No branches or pull requests

2 participants