-
Notifications
You must be signed in to change notification settings - Fork 46
Open
Labels
4.7.0Label for General Availability Release of APIM 4.7.0Label for General Availability Release of APIM 4.7.0BugFixingTracks the bugs to be fixed for APIMTracks the bugs to be fixed for APIMType/Bugjdk21
Milestone
Description
Description
Description
In WSO2 API Manager 4.7.0, there appears to be a permission regression for Tenant Administrators using the Carbon Management Console. When a Super Admin updates the Resident Identity Provider settings, the request succeeds. However, when a Tenant Admin (e.g., admin@wso2.com) attempts to update their tenant's Resident Identity Provider settings, the backend rejects the POST request with a 403 Forbidden error.Other cases such as users adding,Resident service provider updating as well.

Steps to Reproduce
- Start the WSO2 APIM 4.7.0 server.
- Create a new tenant (e.g., wso2.com).
- Log into the Carbon Management Console (https://localhost:9443/carbon) using the Tenant Admin credentials (e.g., admin@wso2.com).
- On the left sidebar, navigate to Main -> Identity -> Identity Providers -> Resident.
- Expand any accordion (e.g., Account Management Policies -> User Self Registration) and toggle a setting.
- Scroll to the bottom and click Update.
Version
WSO2 API Manger 4.7.0-m1
Environment Details (with versions)
OS: Ubuntu 24
DB: MySQL 8.0
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
4.7.0Label for General Availability Release of APIM 4.7.0Label for General Availability Release of APIM 4.7.0BugFixingTracks the bugs to be fixed for APIMTracks the bugs to be fixed for APIMType/Bugjdk21