プロジェクト

全般

プロフィール

Vote #64624

未完了

Link to Changesets is shown to User without credential

Admin Redmine さんがほぼ2年前に追加. ほぼ2年前に更新.

ステータス:
New
優先度:
通常
担当者:
-
カテゴリ:
Permissions and roles_17
対象バージョン:
-
開始日:
2009/02/09
期日:
進捗率:

0%

予定工数:
category_id:
17
version_id:
0
issue_org_id:
2703
author_id:
3094
assigned_to_id:
0
comments:
2
status_id:
1
tracker_id:
1
plus1:
0
affected_version:
closed_on:
affected_version_id:
ステータス-->[New]

説明

The link to a changeset, which updated a ticket status, in ticket comments is shown to users, even if they dont have the creadentials to view the changeset.

So the user gets a "you're not allowed to access this" error page on accidently clicking on the link.


journals

I think it's a much more general issue : nearly wherever you are in Redmine, there can be links you can't follow if you do not have the "View" permission on the section/module. It might be difficult to do this without coupling links parsing and permissions... Any thought about that ?
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------

Admin Redmine さんがほぼ2年前に更新

  • カテゴリPermissions and roles_17 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0