Project

General

Profile

Actions

Bug #15270

closed

Need to prevent users from viewing items not in their organization

Added by Walden Raines over 8 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
API
Target version:
Difficulty:
medium
Triaged:
Fixed in Releases:
Found in Releases:

Description

Users are able to view some details of items that don't belong to their org if they visit the URL directly. This should not be so.

Steps to Reproduce

  1. Ensure you have items in Org 1
  2. Create an additional org (Org 2) if you don't already have one
  3. Create an additional non-admin user with the "viewer" role and place them in Org 2
  4. With the user created in step 3 go to a url for an item in Org 1
  5. Note that you can usually see the details of the item (product for instance)

Related issues 1 (1 open0 closed)

Related to Foreman - Tracker #10022: Taxonomies related issuesNew04/05/2015

Actions
Actions

Also available in: Atom PDF