Skip to content

RBAC bypass via "Copy Page" page action #11438

@nateKlaux

Description

@nateKlaux

Which Fern component?

Fern Docs

How urgent is this?

P1 - High (Strongly needed)

What's the issue?

Steps to reproduce:

  1. Set up RBAC within an.mdx page - use various role and roles you test accont wont have access to.
  2. Nav to page and click Copy page button.
  3. Paste result to see raw content that your role shouldn't have accses to.

Expected: Copying page should respect RBAC roles
Actual: Copying page ignores RBAC roles

Fern CLI & Generator Versions

Fern CLI version: 2.8.2

Workaround

Disable copy page button (not ideal, button is cool feature)

Are you interested in contributing a fix?

No

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions