Project

General

Profile

Bug #30993

HRT endpoint enables owner in strong params definition

Added by Marek Hulán 6 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Host registration
Target version:
-
Difficulty:
Triaged:
No
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

While it does no harm, the strong params whitelist contains the owner https://github.com/theforeman/foreman/pull/8018/files/71f59ba79a611232ea93ae32847b3d159125dba5#diff-df936dd14181cb268280386173da4a5aR25

Only owner_id and owner_type are harfmul, however this should not be allowed anyway.


Related issues

Related to Foreman - Feature #30440: Simple & automatic host registration WFNew

Associated revisions

Revision 4e66ddb2 (diff)
Added by Leos Stejskal 6 months ago

Fixes #30993 - HRT endpoint enables owner in strong params definition (#8049)

History

#1 Updated by Marek Hulán 6 months ago

  • Related to Feature #30440: Simple & automatic host registration WF added

#2 Updated by The Foreman Bot 6 months ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/8049 added

#3 Updated by The Foreman Bot 6 months ago

  • Fixed in Releases 2.3.0 added

#4 Updated by Leos Stejskal 6 months ago

  • Status changed from Ready For Testing to Closed

#5 Updated by Tomer Brisker 5 months ago

  • Category set to Host registration

Also available in: Atom PDF