Continuum
  1. Continuum
  2. CONTINUUM-1867

Project group admin should not be able to grant system-wide roles to himself

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 1.2
    • Fix Version/s: 1.2
    • Component/s: Web - Security
    • Labels:
      None

      Description

      As a project group admin for a single group, I am able to edit my user account and grant any role up to and including system administrator.

      A project group admin should be able to grant the roles for his own project group to other users. He should not be able to elevate his own permissions.

        Issue Links

          Activity

          Hide
          Wendy Smoak added a comment -

          Attaching continuum-user-edit.pdf showing all the options available to a user who currently only has a single project group admin role.

          The first page of the user edit form showing the effective roles can be seen attached to CONTINUUM-1865.

          Show
          Wendy Smoak added a comment - Attaching continuum-user-edit.pdf showing all the options available to a user who currently only has a single project group admin role. The first page of the user edit form showing the effective roles can be seen attached to CONTINUUM-1865 .
          Hide
          jzurbano added a comment -
          Show
          jzurbano added a comment - Fix in http://jira.codehaus.org/browse/REDBACK-160 will also fix this.
          Hide
          Wendy Smoak added a comment -

          We'll need a new release of Redback to fix this.

          Show
          Wendy Smoak added a comment - We'll need a new release of Redback to fix this.
          Hide
          Olivier Lamy (*$^¨%`£) added a comment -

          upgrade to redback 1.1.1 done in rev 696596
          Thanks for the fast release

          Show
          Olivier Lamy (*$^¨%`£) added a comment - upgrade to redback 1.1.1 done in rev 696596 Thanks for the fast release

            People

            • Assignee:
              Olivier Lamy (*$^¨%`£)
              Reporter:
              Wendy Smoak
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development