Right now ACLs are called after before remote hook. That means this stack of calls:
- Before remote Hook
- ACL
- Remote method
- After remote hook
I'd expect ACLs to be checked prior calling before remote hooks and not the other way round.
Example:
Event.beforeRemote("prototype.__unlink__guests", function(ctx, modelInstance, next){
console.log("before remote hook");
next();
});
with this ACL
{
"accessType": "*",
"principalType": "ROLE",
"principalId": "$everyone",
"permission": "DENY",
"property": "__unlink__guests"
}
Even though the Loopback explorer displays a 401 error, the console displays "before remote hook". In my opinion, this should not be the case.
Right now ACLs are called after before remote hook. That means this stack of calls:
I'd expect ACLs to be checked prior calling before remote hooks and not the other way round.
Example:
with this ACL
Even though the Loopback explorer displays a 401 error, the console displays "before remote hook". In my opinion, this should not be the case.