A confidential issue (OD-2192)
alion opened 1 year ago

I found a related issue with OD-2175 when a issue link to a confidential issue, thus unauthorized user can saw a child issue( the confidential issue ) in the issue title, but click the child issue, an error "You are not allowed to perform this operation" happend.

Is that right?

  • Robin Shen commented 1 year ago

    Fixed via OD-2175 as well

  • Robin Shen changed state to 'Closed' 1 year ago
    Previous Value Current Value
    Open
    Closed
  • alion changed state to 'Open' 1 year ago
    Previous Value Current Value
    Closed
    Open
  • Robin Shen commented 1 year ago

    This has been addressed (but not released yet). Any reason reopening this?

  • alion commented 1 year ago

    I found the issue still existing。

    confidential.png err.png

    how to reproduce

    1. two user, xy and xy1, xy1 only has project permission(myPrivate), two issue, Normal Issue with a child issue(confidential issue) link
    2. xy1 has no authrorization to the confidential issue
    3. xy1 can access issue (Normal Issue with a child issue(confidential issue) link)
    4. xy1 can click the Child issue, and saw the confidential issue title
    5. xy1 click the confidential issue title, error
  • Robin Shen changed state to 'Closed' 1 year ago
    Previous Value Current Value
    Open
    Closed
  • Robin Shen commented 1 year ago

    Issue is fixed but not released. Please wait for the issue to be released.

  • alion commented 1 year ago

    I cloned latest code , include OD-2175 commits

  • Robin Shen commented 1 year ago

    Fixed at my side, but not pushed yet. Please wait for the release.

  • alion commented 1 year ago

    So that's it. thank you

issue 1/1
Type
Question
Priority
Normal
Assignee
Labels
No labels
Issue Votes (0)
Watchers (2)
Reference
OD-2192
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover