Skip to content

Built-in models not affected by acl generator #1582

Description

@duckontheweb

Using scl loopback:acl on built-in model Role has no effect on remote restrictions. I am trying to make Roles accessible only to a superuser admin and started by making it public and then attempted to restrict access to all using:

$ slc loopback:acl
? Select the model to apply the ACL entry to: Role
? Select the ACL scope: All methods and properties
? Select the access type: All (match all types)
? Select the role: All users
? Select the permission to apply: Explicitly deny access

However, I still have unauthenticated acces to the model's REST API for all methods.

Modifying server/model-config.json does the trick, but the documentation seemed to suggest that I could do this with the generator instead.

I'm new to this, so it's possible I've just missed something small. I appreciate the help.

Jon

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions