View Issue Details

IDProjectCategoryView StatusLast Update
000868510000-012: DiscoverySpecpublic2024-03-20 20:00
ReporterChristian Zugfil Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Product Version1.05.02 
Fixed in Version1.05.04 RC1 
Summary0008685: UpdateApplication allows users with "DiscoveryAdmin" rights to change the ApplicationUri
Description

Referring to "6.6.7 Update Application"

Section does not restrict changes to specific fields of ApplicationRecordDataType.
Changing the ApplicationUri has severe consequences, creating an inconsistency with the already issued certificates.
Consider restricting the change of the ApplicationUri to at least SecurityAdmin rights because renewing of affected issued certificates is required to prevent breaking communications or prevent the ApplicationUri from being changed at all after registration.

TagsNo tags attached.
Commit Version1.05.04 RC
Fix Due Date

Activities

Randy Armstrong

2023-03-23 19:07

administrator   ~0019012

Need to disable updates to ApplicationUri - if it needs to changed then a new record needs to be created.

Jim Luth

2023-03-23 19:08

administrator   ~0019013

Agreed to disallow changing the ApplicationURI in UpdateApplication.

Randy Armstrong

2024-03-17 09:09

administrator   ~0020913

Added:

When updating an existing Application the ApplicationUri cannot be changed. If it is changed the Method returns Bad_WriteNotSupported

Jim Luth

2024-03-20 20:00

administrator   ~0020983

Agreed to changes in Dallas F2F.

Issue History

Date Modified Username Field Change
2023-02-09 14:30 Christian Zugfil New Issue
2023-03-23 19:07 Randy Armstrong Note Added: 0019012
2023-03-23 19:07 Randy Armstrong Assigned To => Randy Armstrong
2023-03-23 19:07 Randy Armstrong Status new => assigned
2023-03-23 19:08 Jim Luth Note Added: 0019013
2024-03-17 09:09 Randy Armstrong Status assigned => resolved
2024-03-17 09:09 Randy Armstrong Resolution open => fixed
2024-03-17 09:09 Randy Armstrong Fixed in Version => 1.05.04 RC1
2024-03-17 09:09 Randy Armstrong Note Added: 0020913
2024-03-20 20:00 Jim Luth Status resolved => closed
2024-03-20 20:00 Jim Luth Commit Version => 1.05.04 RC
2024-03-20 20:00 Jim Luth Note Added: 0020983