Files
releases/topdown
Johan Fylling 62834a22a6 Asserting every domain is an collection type before evaluation (#6763)
Fixing an issue where a non-collection `every`-domain didn’t fail evaluation.
Removing a possible attack surface, where an attacker with the ability to craft portions of the input document could replace a value with an expected collection type, that is known to be processed by an `every`-statement, with a non-collection value and thereby would cause the policy to accept a query that should otherwise be rejected.

Fixes: #6762
Signed-off-by: Johan Fylling <johan.dev@fylling.se>
2024-05-28 10:16:58 +02:00
..
2020-03-01 16:31:18 -08:00
2017-07-10 08:51:38 -07:00
2017-11-09 09:07:48 -08:00
2022-03-28 07:24:21 +02:00
2022-03-28 07:24:21 +02:00
2022-10-27 13:35:39 +02:00
2023-06-22 15:23:05 +01:00