Defect #16743

Project list lists all projects, even if user is not added to them

Added by Peter L. over 4 years ago. Updated over 4 years ago.

Status:ClosedStart date:
Priority:HighDue date:
Assignee:-% Done:

0%

Category:Accounts / authentication
Target version:-
Resolution:Invalid Affected version:2.5.1

Description

I added a new user group called "external employees" and just created a user for it.

When I log in, i can already see all projects - even when I have not added the external user to any project.
This seems like a security problem to me?

History

#1 Updated by Peter L. over 4 years ago

I meant that i created the group without ANY rights!

#2 Updated by Rafał Lisowski over 4 years ago

You sure the projects are not public?
I use version 2.5.1 and project list works as expected.

Peter L. wrote:

I meant that i created the group without ANY rights!

#3 Updated by Peter L. over 4 years ago

  • Status changed from New to Resolved

Damn, thanks! Was set to public...

But could you maybe tell me, to hide the roadmap?
I just want a user, which can add tickets and see/change/delete only his own tickets? And not see the roadmap versions?
I'm somehow too dumb or its not possible?

Thanks!

#4 Updated by Rafał Lisowski over 4 years ago

That plugin may be helpfull for you https://github.com/efigence/redmine_project_form_extended

Damn, thanks! Was set to public...

I think it's not possible right now see http://www.redmine.org/projects/redmine/wiki/RedmineProjectSettings#Core-modules
There is "Manage version" permission for role (Administartino -> Roles and permissions -> some role) so you can disable adding new versions for role.

But could you maybe tell me, to hide the roadmap?
I just want a user, which can add tickets and see/change/delete only his own tickets? And not see the roadmap versions?

#5 Updated by Peter L. over 4 years ago

Hmm ok..

Thanks for your answers!

#6 Updated by Jean-Philippe Lang over 4 years ago

  • Status changed from Resolved to Closed
  • Resolution set to Invalid

Also available in: Atom PDF