Uploaded image for project: 'Continuum'
  1. Continuum
  2. CONTINUUM-1867

Project group admin should not be able to grant system-wide roles to himself

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 1.2
    • Fix Version/s: 1.2
    • Component/s: Web - Security
    • Labels:
      None

      Description

      As a project group admin for a single group, I am able to edit my user account and grant any role up to and including system administrator.

      A project group admin should be able to grant the roles for his own project group to other users. He should not be able to elevate his own permissions.

        Issue Links

          Activity

          Hide
          wsmoak Wendy Smoak added a comment -

          Attaching continuum-user-edit.pdf showing all the options available to a user who currently only has a single project group admin role.

          The first page of the user edit form showing the effective roles can be seen attached to CONTINUUM-1865.

          Show
          wsmoak Wendy Smoak added a comment - Attaching continuum-user-edit.pdf showing all the options available to a user who currently only has a single project group admin role. The first page of the user edit form showing the effective roles can be seen attached to CONTINUUM-1865 .
          Hide
          jzurbano jzurbano added a comment -
          Show
          jzurbano jzurbano added a comment - Fix in http://jira.codehaus.org/browse/REDBACK-160 will also fix this.
          Hide
          wsmoak Wendy Smoak added a comment -

          We'll need a new release of Redback to fix this.

          Show
          wsmoak Wendy Smoak added a comment - We'll need a new release of Redback to fix this.
          Hide
          olamy Olivier Lamy (*$^¨%`£) added a comment -

          upgrade to redback 1.1.1 done in rev 696596
          Thanks for the fast release

          Show
          olamy Olivier Lamy (*$^¨%`£) added a comment - upgrade to redback 1.1.1 done in rev 696596 Thanks for the fast release

            People

            • Assignee:
              olamy Olivier Lamy (*$^¨%`£)
              Reporter:
              wsmoak Wendy Smoak
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development