https://www.redmine.org/https://www.redmine.org/favicon.ico?16793021292013-12-31T20:12:01ZRedmineRedmine - Defect #15789: Users can see all groups when adding a filter "Assignee's Group"https://www.redmine.org/issues/15789?journal_id=540742013-12-31T20:12:01ZMischa The Evil
<ul><li><strong>Related to</strong> <i><a class="issue tracker-2 status-5 priority-4 priority-default closed" href="/issues/11724">Feature #11724</a>: Prevent users from seeing other users based on their project membership</i> added</li></ul> Redmine - Defect #15789: Users can see all groups when adding a filter "Assignee's Group"https://www.redmine.org/issues/15789?journal_id=544262014-01-21T13:32:03ZMarkus Peter
<ul></ul><p>A solution would be to <em>only list groups which are linked to a role in the current project</em>.</p>
<p>In our case (a group for each client), this would effectively prevent our clients from seeing each other.<br />We now have to link all client users directly to their projects in order to bypass the creation of a group.</p> Redmine - Defect #15789: Users can see all groups when adding a filter "Assignee's Group"https://www.redmine.org/issues/15789?journal_id=563852014-05-19T09:10:31ZRafaĆ Lisowski
<ul><li><strong>File</strong> <a href="/attachments/11641">0001-redmine-issue-15789.patch</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/11641/0001-redmine-issue-15789.patch">0001-redmine-issue-15789.patch</a> added</li></ul><p>I just disabled filter by group. No one use it at my company so it was the easiest way to prevent data leakage.<br />I don't have time now to impelement Marcus Peter solution: "only list groups which are linked to a role in the current project".</p> Redmine - Defect #15789: Users can see all groups when adding a filter "Assignee's Group"https://www.redmine.org/issues/15789?journal_id=597252014-11-11T13:22:08ZJean-Philippe Langjp_lang@yahoo.fr
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Closed</i></li><li><strong>Assignee</strong> set to <i>Jean-Philippe Lang</i></li><li><strong>Target version</strong> set to <i>3.0.0</i></li><li><strong>Resolution</strong> set to <i>Fixed</i></li></ul><p>Fixed by <a class="changeset" title="Adds a role setting for controlling visibility of users: all or members of visible projects (#117..." href="https://www.redmine.org/projects/redmine/repository/svn/revisions/13584">r13584</a>. Depending on Users visibility setting on roles, the group filter will list groups linked to visible projects only.</p>