flagsmith icon indicating copy to clipboard operation
flagsmith copied to clipboard

Add missing `permission_classes` / `get_permissions` to views

Open khvn26 opened this issue 1 year ago • 0 comments

The views listed below need to be updated with permission_classes / get_permissions.

  • api/integrations/slack/views.py:SlackGetChannelsViewSet — potentially leaks Slack channels accessible to previously created integration

The following views are protected by admin login but have no permissions at class or action level:

  • api/sales_dashboard/views.py:OrganisationList
  • api/sales_dashboard/views.py:EmailUsage

khvn26 avatar Aug 22 '24 17:08 khvn26