Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Purpose of the /token/create api ? #530

Open
babyangel0307 opened this issue Jul 27, 2018 · 0 comments
Open

Purpose of the /token/create api ? #530

babyangel0307 opened this issue Jul 27, 2018 · 0 comments

Comments

@babyangel0307
Copy link

HI developers
I'm confusing on the /token/create api.
May i know the purpose of this api?

Since i think it has a security hole on it.
A client user can grant any permission according to the following flow:

  1. A client user login itself
  2. Access token of client user default has MANAGE_TOKEN permission
  3. Client user can call /token/create api with ANY permission or User ID
    In this case, client can create an admin token or ANY permission token
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant