If you add a watcher to an issue, they should have rights to view it.
Hey Guys and Gals,
Redmine is awesome! I have been using it for a while and I have a slight mod. My issue is explained best by example:
- Bob is a user
- Bob only has permissions to see his issues or issues that have been assigned to him
- I want to add Bob as a watcher to an issue so that he may see it (would be nice if he could also add comments/updates)
- If I add Bob as a watcher, he does not see it because the issue is not assigned to him and he is not the creator
My fix is attached in the patch. This may not suite everyone but I thought I would share and ask for feedback.
Would people find this useful?
#3 Updated by fangzheng (方正) over 7 years ago
Could it cause some rights issue?
I'm a developer of project A, and Bob is a developer of project B.
We should only see our respective projects, for some reasons.
Then I add Bob as a watcher to an issue of my project A (on purpose or not). If he has permissions to see the issue, he will also have the permissions of my project A. That's dangerous, I think...
Please let me know if I misunderstand. Thanks!