Bug #2855
Limit Metacat's MN.getLogRecords to CN-only access
Status:
Closed
Priority:
Normal
Assignee:
Ben Leinfelder
Category:
-
Target version:
-
Start date:
2012-06-05
Due date:
% Done:
100%
Milestone:
CCI-1.0.0
Product Version:
*
Story Points:
Sprint:
Description
Currently Metacat allows log record reading by anyone and releases only records for PIDs that the caller has "read" access to.
This is still quite liberal and allows pretty much anyone to glean usage statistics for objects in the system - for good and bad.
This will have impacts on the MN integration tests that expect to be able to read log entries.