Skip to content

Avatar Authorization Bug #19

@msesterhenn

Description

@msesterhenn

The method /users/:userId/avatar seems to check the user permission to update avatar, even when an administrator(higher-privileged user) runs it.

When the user which owns the avatar can't change the avatar the api will reject the request, regardless of the executor.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions