jira.codehaus.org

  • Log In Access more options
    • Online Help
    • Keyboard Shortcuts
    • About JIRA
    • JIRA Credits
    • What?s New
  • Dashboards Access more options (Alt+d)
  • Projects Access more options (Alt+p)
  • Issues Access more options (Alt+i)
  • Continuum
  • CONTINUUM-1919

'Project Developer' role has rights to delete project group to which he is assign to.

  • Log In
  • Views
    • XML
    • Word
    • Printable

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Major Major
  • Resolution: Fixed
  • Affects Version/s: 1.2
  • Fix Version/s: 1.2.1
  • Component/s: Security
  • Labels:
    None
  • Complexity:
    Intermediate

Description

Developer should be able to delete projects from the group, but not the group itself.

  • Options
    • Sort By Name
    • Sort By Date
    • Ascending
    • Descending
    • Download All

Attachments

  1. Text File
    continuum-1919-continuum-security.patch
    07/Oct/08 4:22 AM
    1 kB
    Jevica Arianne B. Zurbano
  2. Text File
    continuum-1919-security.patch
    08/Oct/08 1:03 AM
    1 kB
    Jevica Arianne B. Zurbano

Issue Links

depends upon

Improvement - An improvement or enhancement to an existing feature or task. CONTINUUM-1925 Ability to edit role's permissions

  • Major - Major loss of function.
  • Open - The issue is open and ready for the assignee to start work on it.

Activity

Ascending order - Click to sort in descending order
  • All
  • Comments
  • Work Log
  • History
  • Activity
Hide
Permalink
Jevica Arianne B. Zurbano added a comment - 07/Oct/08 4:22 AM

Attached patch.

  • removed the delete project group right of a Project Developer
Show
Jevica Arianne B. Zurbano added a comment - 07/Oct/08 4:22 AM Attached patch.
  • removed the delete project group right of a Project Developer
Hide
Permalink
Maria Catherine Tan added a comment - 07/Oct/08 10:45 PM

There's a bug with this patch.

As a project group administrator:
I can still delete all project groups. (Ok)

As a project group developer:
I can no longer delete a project group. (OK)

As a project administrator of a certain resource:
I can no longer delete the project group even if I have a project admin role for that group. (BUG)

As a project developer of a certain resource:
I can no longer delete that group. (OK)

Show
Maria Catherine Tan added a comment - 07/Oct/08 10:45 PM There's a bug with this patch. As a project group administrator: I can still delete all project groups. (Ok) As a project group developer: I can no longer delete a project group. (OK) As a project administrator of a certain resource: I can no longer delete the project group even if I have a project admin role for that group. (BUG) As a project developer of a certain resource: I can no longer delete that group. (OK)
Hide
Permalink
Maria Catherine Tan added a comment - 07/Oct/08 11:09 PM

Maybe you could move the "continuum-remove-group" permission under the project-administrator template instead

Show
Maria Catherine Tan added a comment - 07/Oct/08 11:09 PM Maybe you could move the "continuum-remove-group" permission under the project-administrator template instead
Hide
Permalink
Jevica Arianne B. Zurbano added a comment - 08/Oct/08 1:03 AM

continuum-1919-security.patch: "continuum-remove-group" permission moved to Project Administrator template.

Thanks!

Show
Jevica Arianne B. Zurbano added a comment - 08/Oct/08 1:03 AM continuum-1919-security.patch: "continuum-remove-group" permission moved to Project Administrator template. Thanks!
Hide
Permalink
Maria Catherine Tan added a comment - 09/Oct/08 5:59 PM

Fixed in revision 703287. Thanks!

Show
Maria Catherine Tan added a comment - 09/Oct/08 5:59 PM Fixed in revision 703287. Thanks!
Hide
Permalink
Maria Catherine Tan added a comment - 09/Oct/08 6:10 PM

The fix only affects new db.

For existing db, we need a way to edit permissions attached to a role.

Show
Maria Catherine Tan added a comment - 09/Oct/08 6:10 PM The fix only affects new db. For existing db, we need a way to edit permissions attached to a role.

People

  • Assignee:
    Maria Catherine Tan
    Reporter:
    Piotr Krzysztoporski
Vote (8)
Watch (3)

Dates

  • Created:
    06/Oct/08 4:32 AM
    Updated:
    09/Oct/08 11:11 PM
    Resolved:
    09/Oct/08 5:59 PM
  • Atlassian JIRA (v5.0.4#731-sha1:3aa7374)
  • Report a problem
  • Powered by a free Atlassian JIRA open source license for Codehaus. Try JIRA - bug tracking software for your team.