laptop and a wrench

Bug

When a service is configured to allow only a specific set of roles, but its parent folder is configured to allow public access, any user aware of the service's REST endpoint can bypass security and access the service as if it was publicly accessible.

Last Published: August 25, 2014 No Product Found
Bug ID Number NIM075654
SubmittedNovember 22, 2011
Last ModifiedJune 5, 2024
Applies toNo Product Found
Version found10.1
Version Fixed10.1
StatusFixed

Workaround

Instead of configuring security for the service, apply the security settings to the parent folder containing the service.

Steps to Reproduce

Bug ID: NIM075654

Software:

  • No Product Found

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options