continuum-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Wendy Smoak (JIRA)" <j...@codehaus.org>
Subject [jira] Commented: (CONTINUUM-1866) Project group admin should not be able to see projects from other groups in the queues
Date Mon, 29 Sep 2008 20:01:46 GMT

    [ http://jira.codehaus.org/browse/CONTINUUM-1866?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=149309#action_149309
] 

Wendy Smoak commented on CONTINUUM-1866:
----------------------------------------

I agree that might be confusing.  Two things that come to mind:

 - Only show the queues page on the menu of a 'Continuum Group Project User' or above.  That
level already has view access to all projects.

 - Filter the names of the projects I shouldn't be allowed to see, and just display "Other".
 This still exposes the fact that other projects exist on the server, but not their names.


> Project group admin should not be able to see projects from other groups in the queues
> --------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1866
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1866
>             Project: Continuum
>          Issue Type: Bug
>          Components: Web - Security
>    Affects Versions: 1.2
>            Reporter: Wendy Smoak
>            Assignee: Maria Catherine Tan
>             Fix For: 1.2.1
>
>         Attachments: continuum-queues.png
>
>
> As a project group admin for a single group, I have access to the Queues page, and I
can see projects from _other_ groups that I do not have access to.  (It does at least grey
out the 'cancel' icon so that I can't cancel builds.)
> Either the contents of the Queues page must be filtered so that it only includes my own
projects, or it should be removed from my menu.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Mime
View raw message