Project

General

Profile

Actions

Defect #6060

closed

restricted user can access projects list and issue contents

Added by Mario Scondo almost 14 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
High
Assignee:
-
Category:
Accounts / authentication
Target version:
-
Start date:
2010-08-06
Due date:
% Done:

0%

Estimated time:
Resolution:
Invalid
Affected version:

Description

Hello,

I did add a new user with the permission to access the files section of a single project. When the performig a login with this new user I did experience the following problems:

  • the user gets an error message after logging in
  • the list of projects is accessible
  • when entering project via the project list all issues are accessable (of every project).
  • when entering projects, where access has been granted, the checking for permissions seems to work properly. However, I did grant access to the files section, but the sections 'Activity' and 'News' are available, too.

I do set the priority to 'high' because of the possibility to access data within non-public projects.

Actions

Also available in: Atom PDF