Defect #9405
closed
Any user with :log_time permission can edit time entries via context menu
Added by Jevgen Gyrynovych about 13 years ago.
Updated almost 13 years ago.
Description
In Redmine 1.2.0 or later any user can edit any time entries via context menu.
Example url: http://redmine/projects/testproject/time_entries and click right mouse button on any time entries.
img1.png - user have permission to edit any time entries
img2-4.png - user edit time entries without permission on it.
As you can see, user with permissions have icons for edit time report, but user without permissions can do this via context menu anyway.
PS: I set high priority to ticket. I think, this serious defect?
Files
- Category set to Time tracking
- Priority changed from High to Normal
- Priority changed from Normal to High
- Target version set to Candidate for next minor release
Ahh, I see... Thanks for your clarification on this Toshi. I was testing with an account that did not had the :log_time
permission at all :-/
- Target version changed from Candidate for next minor release to 1.2.3
- Status changed from New to Resolved
- Assignee set to Jean-Philippe Lang
Now it work fine. Thanks.
I find some problem after apply the patch - when user tried to update ticket(e.g. nuber_of_ticket/edit), he dont have access to "Log time".
It fix that problem.
I don't know what this patch is supposed to fix but :log_time
should not allow the user to edit time entries.
I fixed a last point in r7924 which may be related to your fix.
- Subject changed from any user can edit time entries via context menu to Any user with :log_time permission can edit time entries via context menu
- Status changed from Resolved to Closed
- Resolution set to Fixed
Also available in: Atom
PDF