Security fixes arrive to dash and list agents

lock
push_pin
done
Beantwortet
0

Hi everyone,

It's generally expected that only list admins can provision list items and dashboard administrators can create list items. Until now though, these could be accomplished using the APIs bypassing security checks. In the current release we have locked this down and now provisioning of the following items are affected:

List Agent: the user is required to have either AdminAll or AdminLists functional rights.
    SaveTaskMenu
    DeleteTaskMenu
    DeleteAppTaskMenus
    SaveWebPanelEntity
    DeleteWebPanel
    DeleteAppWebPanels
 
Dash Agent: the user is required to have either General Administrator, Dashboard Administrator or a System User.
    GetDashAsync
    SaveDashTileAsync
    DeleteDashTileAsync
    SaveDashTilesAsync
 
Only admins should have been performing these operations, so you really shouldn't notice. 😊
 
Best regards

21. Okt. 2025 | 01:24 PM

Alle Antworten (0)

Antwort hinzufügen