Skip to content

ACL by-passing in license version of XOA | Revenue leakage #8390

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
irtaza9 opened this issue Feb 27, 2025 · 1 comment
Open

ACL by-passing in license version of XOA | Revenue leakage #8390

irtaza9 opened this issue Feb 27, 2025 · 1 comment
Labels
Plane To synchronise with plane

Comments

@irtaza9
Copy link

irtaza9 commented Feb 27, 2025

I was trying to add acl on a user from XO. I have a licensed for my XOA. In paid version you are not allowed to use acl and few more features.

The below image is showing this.

Image

But then I configured the JSON-RPC for the same XOA which is paid and signedin via admin user irtaza.hussain and call acl.add method with required payload. In the payload subject is a normal user of my XO which have no acl applied yet and I want to assign a VM to him and object is the VM which I want to assign him as an admin to the VM.

When I called the acl.add method via irtaza.hussain who is an admin user of same host then I get result: true from the JSON-RPC api - means you can use acl feature in normal licensee too. In a good faith I am sharing this with you so you can perform necessary action accordingly.

Image

After acl being applied to the irtazahussain (db3253f7-94a8-4d5d-91c3-c65896e3c4a0) here is the ss

Image

@benjamreis benjamreis added the Plane To synchronise with plane label Mar 14, 2025
@plane-sync-vates
Copy link

Synced Issue with Plane Workspace 🔄

XO-834 ACL by-passing is license version of XOA | Revenue leakage

@irtaza9 irtaza9 changed the title ACL by-passing is license version of XOA | Revenue leakage ACL by-passing in license version of XOA | Revenue leakage Mar 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Plane To synchronise with plane
Projects
None yet
Development

No branches or pull requests

2 participants