PRODSEC-6261 - Add the missing Object Level Authorization call (#1160)

* PRODSEC-6261 Add 'shouldNotGetProcessesByNotInvolvedUser' test

* PRODSEC-6261 Add user validation to 'getProcess' method

* PRODSEC-6261 Add TestRail annotation minor fix
This commit is contained in:
Damian Ujma
2022-06-20 11:59:25 +02:00
committed by GitHub
parent cc9fe10c05
commit 7c0f6998ec
2 changed files with 14 additions and 2 deletions

View File

@@ -511,7 +511,9 @@ public class ProcessesImpl extends WorkflowRestImpl implements Processes
{
throw new InvalidArgumentException("processId is required to get the process info");
}
validateIfUserAllowedToWorkWithProcess(processId);
HistoricProcessInstance processInstance = activitiProcessEngine
.getHistoryService()
.createHistoricProcessInstanceQuery()