Improved Authorization Model Blocks Access for Unauthorized User
It turned out to be possible for users to access data for which they were not authorized via indirect fields. Examples are chain integrations where chain IDs per customer-supplier are recorded on the tables Administrations, Creditors and/or Debtors. If you did not have access to those tables or data in the MKG client, a script using 'indirect fields' could still access them. We have improved the authorization model so that this data is no longer accessible via scripts or API, unless the user is authorized for it. From this version onwards it may happen that authorization is applied that was not previously applied. |
- Published:18 apr 2024 14:53
- Latest update:18 apr 2024 14:53
- TypeRelease notes
- FunctionalityVERBETERD
- Category
- Product
- Version005.078.003
- AvailabilityOpenbaar