Actions
Bug #30993
closedHRT endpoint enables owner in strong params definition
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Host registration
Target version:
-
Description
While it does no harm, the strong params whitelist contains the owner https://github.com/theforeman/foreman/pull/8018/files/71f59ba79a611232ea93ae32847b3d159125dba5#diff-df936dd14181cb268280386173da4a5aR25
Only owner_id and owner_type are harfmul, however this should not be allowed anyway.
Actions