Files
releases/internal
Johan Fylling 62834a22a6 Asserting every domain is an collection type before evaluation (#6763)
Fixing an issue where a non-collection `every`-domain didn’t fail evaluation.
Removing a possible attack surface, where an attacker with the ability to craft portions of the input document could replace a value with an expected collection type, that is known to be processed by an `every`-statement, with a non-collection value and thereby would cause the policy to accept a query that should otherwise be rejected.

Fixes: #6762
Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2024-05-28 10:16:58 +02:00
..
2023-10-26 09:13:56 -07:00
2024-03-25 11:28:12 -07:00
2022-01-29 13:28:54 -08:00
2023-01-11 10:30:48 -08:00
2022-10-27 13:35:39 +02:00