Project

General

Profile

Actions

Defect #25791

closed

Bypass Tracker role-based permissions when copying issues

Added by Shane Coronado almost 7 years ago. Updated almost 7 years ago.

Status:
Closed
Priority:
Normal
Category:
Issues permissions
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Not sure if intended: We use the permission settings for our roles. However, our Developer role is able to create an issue that the role does not have permission to create. This was done by Copying said issue and not changing the Tracker field. By leaving the Tracker field blank, the user is able to create an issue that bypasses the role's permissions.


Files

create_tickets_by_copy.jpg (29.7 KB) create_tickets_by_copy.jpg Shane Coronado, 2017-05-08 21:28
create_tickets_by_copy2.jpg (24.6 KB) create_tickets_by_copy2.jpg Shane Coronado, 2017-05-08 21:28
create_tickets_by_copy3.jpg (20.2 KB) create_tickets_by_copy3.jpg Shane Coronado, 2017-05-08 21:29
create_tickets_by_copy4.jpg (30.4 KB) create_tickets_by_copy4.jpg Shane Coronado, 2017-05-08 21:29
Actions #1

Updated by Toshi MARUYAMA almost 7 years ago

  • Target version set to 3.2.7
Actions #2

Updated by Jean-Philippe Lang almost 7 years ago

  • Status changed from New to Resolved
  • Assignee set to Jean-Philippe Lang
  • Resolution set to Fixed

Fixed in r16569.

Actions #3

Updated by Jean-Philippe Lang almost 7 years ago

  • Subject changed from Bypass Tracker role-based permissions to Bypass Tracker role-based permissions when copying issues
  • Status changed from Resolved to Closed
  • Target version changed from 3.2.7 to 3.3.4

Tracker role-based permissions are not implemented in 3.2.

Actions

Also available in: Atom PDF