Project

General

Profile

Actions

Defect #1730

closed

Private projects with public subprojects disclose the parent project

Added by micah anderson almost 16 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Projects
Target version:
-
Start date:
2008-08-01
Due date:
% Done:

100%

Estimated time:
Resolution:
Fixed
Affected version:

Description

If you create a private project, the project is not visible to users who are not signed in. This is good and what is expected. However, if you add a subproject to this private project and make that subproject public, then the parent project becomes visible in the project list. This is unexpected, and probably should not happen.

This is using 0.7.devel.1625 (MySQL)


Related issues

Has duplicate Redmine - Feature #1542: Viewing links to restricted subprojectsClosed2008-06-28

Actions
Actions #1

Updated by Jean-Philippe Lang almost 16 years ago

then the parent project becomes visible in the project list

What project list exactly ? The drop-down (quick jump) project list or the project list at /projects ?

Actions #2

Updated by micah anderson over 15 years ago

The project list at /projects, as well as the pull down menu and the home page where it says "Latest Projects" all list the parent project that is not marked public.

Actions #3

Updated by Mischa The Evil over 15 years ago

This seems to be fixed in the new 0.8.0-RC1. Just tested it and private parent projects are only showed in the stated views when:
  • the logged-in user has a role on the project itself
  • or when the logged-in user has a role on a child project (though the user receives a 403-error when selecting the parent-project for which he doesn't have a role).

Please provide some feedback of your experiences... ;-)

Actions #4

Updated by micah anderson over 15 years ago

  • Status changed from New to Resolved
  • % Done changed from 0 to 100

Hello,

I've just installed 0.80 and it does indeed look like this has been resolved.

Thanks a lot, redmine is truely great.

Actions #5

Updated by Brad Beattie over 15 years ago

Mischa The Evil wrote:

This seems to be fixed in the new 0.8.0-RC1. Just tested it and private parent projects are only showed in the stated views when [...] the logged-in user has a role on a child project (though the user receives a 403-error when selecting the parent-project for which he doesn't have a role).

We probably shouldn't be displaying links to users that will 403 on them. :(

Actions #6

Updated by Mischa The Evil over 14 years ago

  • Status changed from Resolved to Closed
  • Resolution set to Fixed

Brad Beattie wrote:

Mischa The Evil wrote:

This seems to be fixed in the new 0.8.0-RC1. Just tested it and private parent projects are only showed in the stated views when [...] the logged-in user has a role on a child project (though the user receives a 403-error when selecting the parent-project for which he doesn't have a role).

We probably shouldn't be displaying links to users that will 403 on them. :(

This is fixed in the current trunk (which will become Redmine 0.9.0).

Actions

Also available in: Atom PDF