Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-56155

[kubernetes] Allow non-admin to retrieve nothing from API calls

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Minor Minor
    • kubernetes-plugin
    • None

      Created initially by Keir in https://github.com/jenkinsci/kubernetes-plugin/pull/419.

      The goal is to allow a non-admin user to use the API and do not generate stacktrace. So instead of checking permission we can return an empty list, like proposed by Daniel.

      No security impact in such case. The initial version could have security impact.

            keirbadger Keir Badger
            wfollonier Wadeck Follonier
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: