New Issue Checklist
Issue Description
Since Parse Server 9, logging in with authData fails with Permission denied when public create is disabled on the _User class.
Login with authData uses the same POST /users request as sign-up. The create permission check added in #10268 now runs for this request even when it logs in an existing user and creates nothing. This worked in 8.x, and the REST guide describes this request as returning the existing user with a session token.
Steps to reproduce
- Log in with an auth provider to create a linked user, e.g.
await Parse.User.logInWith('myoauth', { authData }).
- Log out.
- Disable public
create on _User (classLevelPermissions.create: {}).
- Log in again with the same
authData.
Actual Outcome
The login fails with Permission denied (code 119).
Expected Outcome
The existing user is logged in and receives a session token, as in 8.x. Signing up a new user with authData should still be denied.
Environment
Server
- Parse Server version:
9.10.0, also reproduced on alpha (c3b46940)
- Operating system:
Linux (Docker)
- Local or remote host:
Google Cloud
Database
- System (MongoDB or Postgres):
MongoDB
- Database version:
8.0.4 (test suite)
- Local or remote host:
local (test suite)
Client
- SDK:
JavaScript
- SDK version:
8.6.2
Logs
With enableSanitizedErrorResponse: false:
Permission denied for action create on class _User.
at SchemaController.validatePermission
at RestWrite.validateCreatePermission
I have a fix with tests and will open a pull request.
New Issue Checklist
Issue Description
Since Parse Server 9, logging in with
authDatafails withPermission deniedwhen publiccreateis disabled on the_Userclass.Login with
authDatauses the samePOST /usersrequest as sign-up. The create permission check added in #10268 now runs for this request even when it logs in an existing user and creates nothing. This worked in 8.x, and the REST guide describes this request as returning the existing user with a session token.Steps to reproduce
await Parse.User.logInWith('myoauth', { authData }).createon_User(classLevelPermissions.create: {}).authData.Actual Outcome
The login fails with
Permission denied(code 119).Expected Outcome
The existing user is logged in and receives a session token, as in 8.x. Signing up a new user with
authDatashould still be denied.Environment
Server
9.10.0, also reproduced onalpha(c3b46940)Linux (Docker)Google CloudDatabase
MongoDB8.0.4(test suite)local (test suite)Client
JavaScript8.6.2Logs
With
enableSanitizedErrorResponse: false:I have a fix with tests and will open a pull request.