Closed
Bug 315068
Opened 19 years ago
Closed 19 years ago
Edit components
Categories
(Bugzilla :: Administration, task)
Tracking
()
RESOLVED
DUPLICATE
of bug 271596
People
(Reporter: jessn, Unassigned)
Details
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Build Identifier: When granting "Edit components" to a specific user then the user will be able to edit all products also the ones that the user is not a member of. An option restricting this only to the projects that user is a member of would be appreciated. Reproducible: Always Steps to Reproduce: 1. Grant "Edit components" to a certain user 2. Login as the user, who has just been granted the "Edit components" rights. 3. Choose "Products" and try to edit a project the user is not a member of. (the user will succeed in doing this) Actual Results: The user is able to modify all projects whether the user is a member of them of not. Expected Results: The only projects that should be visible to the user with "Edit components" rights, unless the user has administrative rights, should be the projects, which the user is a member of. Please note this bug is marked as an Enhancement Request. By implementing this it will be possible to allow one (or maybe several?) person(s) per project to administrate their own project i.e. components, versions, milestones etc within it and even limit this only to the ones that they are currently a member of for security reasons. In this way all tasks does not depend on a few persons with "global" admin (or like here "Edit components") rights.
Comment 1•19 years ago
|
||
*** This bug has been marked as a duplicate of 271596 ***
Group: webtools-security
Status: UNCONFIRMED → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•