Closed Bug 315068 Opened 19 years ago Closed 19 years ago

Edit components

Categories

(Bugzilla :: Administration, task)

x86
Windows XP
task
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 271596

People

(Reporter: jessn, Unassigned)

Details

User-Agent:       Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Build Identifier: 

When granting "Edit components" to a specific user then the user will be able to edit all products also the ones that the user is not a member of.

An option restricting this only to the projects that user is a member of would be appreciated.

Reproducible: Always

Steps to Reproduce:
1. Grant "Edit components" to a certain user
2. Login as the user, who has just been granted the "Edit components" rights.
3. Choose "Products" and try to edit a project the user is not a member of. (the user will succeed in doing this)

Actual Results:  
The user is able to modify all projects whether the user is a member of them of not.

Expected Results:  
The only projects that should be visible to the user with "Edit components" rights, unless the user has administrative rights, should be the projects, which the user is a member of.

Please note this bug is marked as an Enhancement Request.

By implementing this it will be possible to allow one (or maybe several?) person(s) per project to administrate their own project i.e. components, versions, milestones etc within it and even limit this only to the ones that they are currently a member of for security reasons.

In this way all tasks does not depend on a few persons with "global" admin (or like here "Edit components") rights.

*** This bug has been marked as a duplicate of 271596 ***
Group: webtools-security
Status: UNCONFIRMED → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
Blocks: 367872
No longer blocks: 367872
You need to log in before you can comment on or make changes to this bug.