Anonymous Login
2019-04-24 18:50 PDT

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0001702v3.4 Release (Current)User Adminpublic2019-01-03 12:53
Reporteropto 
Assigned Tocaseydk 
PrioritynormalSeverityminorReproducibilityhave not tried
StatusclosedResolutionfixed 
Product Version 
Target VersionFixed in Version 
Summary0001702: Task Permissions gone crazy?
Descriptionsetting a task: deny access for a user with allow all on all non admin modules. he can see the task although access is denied.
This is probably due to the fact that getTaskTree does not respect permissions, it just shows all tasks (in vw_tasks.php

TagsNo tags attached.
Attached Files

-Relationships
+Relationships

-Notes

~0003858

caseydk (administrator)


Added the check using canView() in the tree.

Ref: https://github.com/web2project/web2project/commit/beacc8e336955be22b7ac2e3565143f0ebd3d190

~0003963

caseydk (administrator)

In the 31 Dec 2018 release: http://docs.web2project.net/release-notes/3.4.html
+Notes

-Issue History
Date Modified Username Field Change
2016-07-05 00:35 opto New Issue
2016-07-05 09:38 opto Summary Permissions gone crazy? => Task Permissions gone crazy?
2016-07-05 09:38 opto Description Updated View Revisions
2016-12-26 23:34 caseydk Project v3.3 Release => v3.4 Release (Current)
2016-12-29 21:08 caseydk Assigned To => caseydk
2016-12-29 21:08 caseydk Status new => resolved
2016-12-29 21:08 caseydk Resolution open => fixed
2016-12-29 21:08 caseydk Note Added: 0003858
2019-01-03 12:53 caseydk Note Added: 0003963
2019-01-03 12:53 caseydk Status resolved => closed
+Issue History