Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Adding clarification that sub-admin roles should not be able to chang…
…e their own privileges (#1451) Cherry-picked from #1440 This was noticed in a recent internal pentest of RBAC. We need to clarify that it is necessary to explicitly deny the ability to change your own privileges if you copy the admin role (otherwise the new role is essentially unconstrained). Co-authored-by: Phil Wright <[email protected]>
- Loading branch information