<< Back to previous view |
[QB-979] Workspace permission allows users to see workspaces for other configurations
|
|
Status: | Resolved |
Project: | QuickBuild |
Component/s: | None |
Affects Version/s: | 3.1.48 |
Fix Version/s: | 3.1.53 |
Type: | Bug | Priority: | Major |
Reporter: | Karim Heredia | Assigned To: | Unassigned |
Resolution: | Fixed | Votes: | 0 |
Remaining Estimate: | Unknown | Time Spent: | Unknown |
Original Estimate: | Unknown | ||
Environment: | Linux 64-bit |
Description |
We are planning to open workspace access to owners of configurations, but we don't want them to see other workspaces.
We ran the following test: 1. Created configurations like this: Root | -------> Config A | -------> Config B 2. A user was configured so he could see only build logs at the Root level and can see Config A's workspace. 3. User clicks on Root from Configurations tab. There is no workspace link (correct). 4. User clicks on Config A from Configurations tab. There is a workspace link pointing to Config A's workspace (correct). 5. If user clicks on the Root link at the top of the page while the Config A workspace is open, the user can see the Root workspace and therefore also Config B's workspace (incorrect). |