mirror of
https://github.com/project-zot/zot.git
synced 2025-02-17 23:45:36 -05:00
GHSA-c9p4-xwr9-rfhx authN/authZ creds are added to the request context so that they can be tracked and enforced in the various subsystems. However, it was previously a appended list (incorrectly); consequently, even if the user has been removed from the group configuration, the user could still log in. Signed-off-by: Ramkumar Chinchani <rchincha.dev@gmail.com> |
||
---|---|---|
.. | ||
boltdb.go | ||
boltdb_test.go | ||
buckets.go | ||
parameters.go |