MantisBT - v3.4 Release (Current)
View Issue Details
0001702v3.4 Release (Current)User Adminpublic2016-07-05 00:352019-01-03 12:53
Reporteropto 
Assigned Tocaseydk 
PrioritynormalSeverityminorReproducibilityhave not tried
StatusclosedResolutionfixed 
PlatformOSOS Version
Product Version 
Target VersionFixed in Version 
Summary0001702: Task Permissions gone crazy?
Descriptionsetting a task: deny access for a user with allow all on all non admin modules. he can see the task although access is denied.
This is probably due to the fact that getTaskTree does not respect permissions, it just shows all tasks (in vw_tasks.php

TagsNo tags attached.
Attached Files

Notes
(0003858)
caseydk   
2016-12-29 21:08   

Added the check using canView() in the tree.

Ref: https://github.com/web2project/web2project/commit/beacc8e336955be22b7ac2e3565143f0ebd3d190
(0003963)
caseydk   
2019-01-03 12:53   
In the 31 Dec 2018 release: http://docs.web2project.net/release-notes/3.4.html

Issue History
2016-07-05 00:35optoNew Issue
2016-07-05 09:38optoSummaryPermissions gone crazy? => Task Permissions gone crazy?
2016-07-05 09:38optoDescription Updatedbug_revision_view_page.php?rev_id=152#r152
2016-12-26 23:34caseydkProjectv3.3 Release => v3.4 Release (Current)
2016-12-29 21:08caseydkAssigned To => caseydk
2016-12-29 21:08caseydkStatusnew => resolved
2016-12-29 21:08caseydkResolutionopen => fixed
2016-12-29 21:08caseydkNote Added: 0003858
2019-01-03 12:53caseydkNote Added: 0003963
2019-01-03 12:53caseydkStatusresolved => closed