Defect #888

Jump to Project reveals names of parent projects to unprivileged logins

Added by Mike Carter over 11 years ago. Updated over 10 years ago.

Status:ClosedStart date:2008-03-19
Priority:NormalDue date:
Assignee:-% Done:

0%

Category:Permissions and roles
Target version:-
Resolution:Fixed Affected version:

Description

The hierarchical menu in the "Jump to Project" dropdown lists the names of parent projects to which the user does not have permissions.
Users receive a 403 Not Authorized warning, but we'd prefer they not even know the names of the parent projects.

Otherwise, thanks for a great project!


Related issues

Related to Redmine - Feature #8904: Parent project's name should be visible for Subprojects New 2011-07-26

History

#1 Updated by Mischa The Evil almost 11 years ago

This seems to have been fixed somewhere on this 0.7-branch. Just tested this with the new 0.8.0-RC1 and only projects of which the user is a member of (has a role for) are shown in the drop-down menu.

Can you confirm and resolve the issue?

#2 Updated by Jean-Philippe Lang over 10 years ago

  • Status changed from New to Closed
  • Resolution set to Fixed

This is fixed in current trunk.

#3 Updated by Toshi MARUYAMA over 4 years ago

  • Related to Feature #8904: Parent project's name should be visible for Subprojects added

Also available in: Atom PDF