Continuum
  1. Continuum
  2. CONTINUUM-1889

Project group admin should not be able to move a project into a group he does not have access to

    Details

    • Type: Bug Bug
    • Status: Closed Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 1.2
    • Fix Version/s: 1.2.1
    • Component/s: Project Grouping
    • Labels:
      None
    • Complexity:
      Intermediate
    • Number of attachments :
      0

      Description

      On the editProjectGroup.action page, a project group admin is allowed to move a project into any other group, even if he does not have admin permissions there.

      The "Move to Group" drop downs should only contain groups for which the current user is an admin, and moves to other groups should be prevented.

        Activity

        Hide
        Emmanuel Venisse added a comment -

        Done.

        Fixed in rev.698817

        Show
        Emmanuel Venisse added a comment - Done. Fixed in rev.698817
        Hide
        Wendy Smoak added a comment -

        Emmanuel, does this actually prevent the move from taking place, or only the wrong projects from showing in the select list?

        That is, could I still do it by constructing a url or form with the right values, and submitting it?

        Show
        Wendy Smoak added a comment - Emmanuel, does this actually prevent the move from taking place, or only the wrong projects from showing in the select list? That is, could I still do it by constructing a url or form with the right values, and submitting it?
        Hide
        Emmanuel Venisse added a comment -

        Good question, I'll test it.

        Show
        Emmanuel Venisse added a comment - Good question, I'll test it.
        Hide
        Emmanuel Venisse added a comment -

        Fixed.
        Committed in r.699171

        Show
        Emmanuel Venisse added a comment - Fixed. Committed in r.699171

          People

          • Assignee:
            Emmanuel Venisse
            Reporter:
            Wendy Smoak
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: