Activiti REST and permissions

Question asked by r3dge on May 27, 2015
Latest reply on May 29, 2015 by r3dge

With activiti explorer i have created a new user called "r3dge", member of the group "cpe". Then i have sent a REST request with the user "r3dge" :

GET http://localhost:8080/activiti-rest/service/runtime/tasks

In the response body i found all tasks pending for all groups and not only task assigned to group my user is taking part.

Does that means that there are no permissions applied in the REST API ?