Skip to content

Security issue in the way tiled writer is used #1412

@ZohebShaikh

Description

@ZohebShaikh

Currently metadata data is added to the run metadata by blueapi here , This is used by the TiledWriter here

This opens up a potential security vulnerability in which User A with permission to write to session 1 can write to all the sessions that the service_account has access to mid plan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    c: contextexternalIntegrations with the outside worldneeds investigationUnclear why something happens or what needs doing

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions