Rights management doesn't handle user's budgets #57
Loading…
x
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently all API endpoints just check for a valid token. So any user could read any other user's budgets. We should check if a user actually has access to a specific budget and its history.