Any user with :log_time permission can edit time entries via context menu
|Assignee:||Jean-Philippe Lang||% Done:|
In Redmine 1.2.0 or later any user can edit any time entries via context menu.
Example url: http://redmine/projects/testproject/time_entries and click right mouse button on any time entries.
img1.png - user have permission to edit any time entries
img2-4.png - user edit time entries without permission on it.
As you can see, user with permissions have icons for edit time report, but user without permissions can do this via context menu anyway.
PS: I set high priority to ticket. I think, this serious defect?
Fixed: log time form not displayed on issue edit with :log_time permission only (#9405).
#4 Updated by Toshi MARUYAMA over 7 years ago
This line has a bug.