You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
New projects / versions are created in root though project access should be limited by porfolio access control policy to one existing (parent) project.
Steps to Reproduce
Create a new project "Parent project"
Set up a team "Gitlab-CI publish only" with minimal permissions to upload SBOMs and create new projects (BOM_UPLOAD, PROJECT_CREATION_UPLOAD)
Enable portfolio access control
For team "Gitlab-CI publish only" only enable project access only to "Parent project"
POST a new SBOM using CURL without parameter "parentName" or "parentUUID"
Expected Behavior
POST should fail because of the access limitation by porfolio access control policy
thomashucke
changed the title
Porfolio access control not respected in API requests?
Portfolio access control not respected in API requests?
Nov 13, 2024
Current Behavior
New projects / versions are created in root though project access should be limited by porfolio access control policy to one existing (parent) project.
Steps to Reproduce
Expected Behavior
POST should fail because of the access limitation by porfolio access control policy
Dependency-Track Version
4.12.1
Dependency-Track Distribution
Container Image
Database Server
PostgreSQL
Database Server Version
No response
Browser
Mozilla Firefox
Checklist
The text was updated successfully, but these errors were encountered: