Skip to content

Fix optional tenancy access checks - #3214

Open
doomedraven wants to merge 3 commits into
masterfrom
fix_tenancy
Open

doomedraven wants to merge 3 commits into
masterfrom
fix_tenancy

Conversation

@doomedraven

Copy link
Copy Markdown
Collaborator

When multitenancy is disabled but WEB_AUTHENTICATION is enabled, access checks now enforce owner/staff-only visibility and mutation rights for private tasks while preserving legacy ownerless tasks. Local admin handling was also corrected for disabled MT mode, and the fallback optional-tenancy helpers now deny access when MT is enabled instead of allowing broad access.

When multitenancy is disabled but WEB_AUTHENTICATION is enabled, access checks now enforce owner/staff-only visibility and mutation rights for private tasks while preserving legacy ownerless tasks. Local admin handling was also corrected for disabled MT mode, and the fallback optional-tenancy helpers now deny access when MT is enabled instead of allowing broad access.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant