eeg_portal/eeg_backend
Bernhard Müller b0145f3b30 fix(security): fix critical security and error handling issues
Security:
- Change permitAll() to denyAll() for unlisted routes
- Add @PreAuthorize to membership endpoints
- Add ownership check in requestMembership
- Use AccessDeniedException instead of SecurityException

Error Handling:
- Add proper exception mapping for IllegalArgumentException (400)
- Add proper exception mapping for IllegalStateException (409)
- Add proper exception mapping for AccessDeniedException (403)
- Remove internal error messages from generic exception handler

Tests:
- Update MembershipServiceTest for new method signature
- Update MeteringPointServiceTest for AccessDeniedException
- All 37 tests passing
2026-07-21 16:27:35 +02:00
..
src fix(security): fix critical security and error handling issues 2026-07-21 16:27:35 +02:00
http-client.private.env.json first working frontend/backend 2026-06-01 16:59:49 +02:00
iam.http refactoring, adaption, community membership handing start implementing 2026-06-15 10:10:33 +02:00
pom.xml complete MaKo consent flow and admin initialization 2026-07-21 10:01:19 +02:00