I think I’ve hit a permissions hole: as a regular authenticated user with no AddContent rights on a target…
I think I’ve hit a permissions hole: as a regular authenticated user with no AddContent rights on a target…: a task in MiMo-V2.6-RL-oss: Agentic RL Environments (MiMo RL release). I also noticed @user info is reachable from a user that doesn’t have guillotina.AccessContent on the context. Expected…
The task
I also noticed @user_info is reachable from a user that doesn’t have guillotina.AccessContent on the context. Expected outcomes: POST .../@duplicate must not allow a request body value such as "check_permission": false to bypass the target container’s content-add permission…
Part of XiaomiMiMo/MiMo-V2.6-RL-oss.