open-certs/oc-backend

[Bug]: Cross Provider access is not restricted

Closed this issue · 7 comments

Preflight Checklist

  • I have read the Contribution.md for this project.
  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue for a feature request that matches the one I want to file, without success.

Version

0.0.1

Current Behavior

Once a user is authenticated, then it can access any user specific api.

But a user authenticated with Github should not be able to access Gitlab or Bitbucket specific apis.

Expected Behavior

There should be a middleware in provider.helper.js which should take a provider as parameter and restricts the users accordingly.

Additional Information

NA

Hello, Please assign me this issue.

@Sukh0204 any update on this??

@Sukh0204 any update on this???

Un-assigning due to no response

Assign this issue to me please!

Sure go head