プロジェクト

全般

プロフィール

Vote #74764

完了

Users can see all groups when adding a filter "Assignee's Group"

Admin Redmine さんが約4年前に追加. 約4年前に更新.

ステータス:
Closed
優先度:
通常
担当者:
-
カテゴリ:
Permissions and roles_17
対象バージョン:
開始日:
2022/05/09
期日:
進捗率:

0%

予定工数:
category_id:
17
version_id:
80
issue_org_id:
15789
author_id:
78159
assigned_to_id:
1
comments:
4
status_id:
5
tracker_id:
1
plus1:
0
affected_version:
closed_on:
affected_version_id:
77
ステータス-->[Closed]

説明

Hello,

I'm going to quote Djordjije who perfectly explained the problem in issue #11724, note 13 (even if issue #11724 has nothing to do with this current issue).

Djordjije Crni wrote:

User can see the names of all groups on Redmine, by selecting issue filter by "Assignee's group"!
This happens even if issue assignment to groups isn't allowed.
I've expected to see only the names of those groups which are assigned to that project in the filter list.
And guess what, almost all group names (in my case) are constructed from two parts: project role and project name. Very original idea, isn't it?
In this case, customer can easily guess names of all projects, which is not acceptible at all.
It seems that current Redmine user/group permission model can't provide reliable customer/project isolation.
"Workaround" could be to give meaningless names to groups, and even better, give meaningless names to projects also?

We have the same issue. We create a group for each customer who is accessing Redmine, and the group name is the customer name. This way, any customer can access our whole customer list.

Thanks in advance for your feedback.


journals

--------------------------------------------------------------------------------
A solution would be to _only list groups which are linked to a role in the current project_.

In our case (a group for each client), this would effectively prevent our clients from seeing each other.
We now have to link all client users directly to their projects in order to bypass the creation of a group.
--------------------------------------------------------------------------------
I just disabled filter by group. No one use it at my company so it was the easiest way to prevent data leakage.
I don't have time now to impelement Marcus Peter solution: "only list groups which are linked to a role in the current project".
--------------------------------------------------------------------------------
Fixed by r13584. Depending on Users visibility setting on roles, the group filter will list groups linked to visible projects only.
--------------------------------------------------------------------------------


related_issues

relates,Closed,11724,Prevent users from seeing other users based on their project membership

Admin Redmine さんが約4年前に更新

  • カテゴリPermissions and roles_17 にセット
  • 対象バージョン3.0.0_80 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0