Currently, the question service does not check the incoming request to see if the user associated with the request is allowed to access it Requirements: - Associated request is only allowed by certain roles Fulfills: FR15.3