View ProjeQtOr On SourceForge.net
ProjeQtOr - Project Management Tool
Support us on Capterra
OIN - Open Invention Network
ProjeQtOr free project management software - Access Rights Issue with Projects listed in the Project ComboBox - ProjeQtOr
 
 

Access Rights Issue with Projects listed in the Project ComboBox

More
10 Oct 2014 22:07 #1 by francis2301
Hi,
I'm facing the following scenario:
I have a user which is configured in the right access form to "access items from its own projects" (complete access to items, but only from projects where s/he is assigned). This user was assigned to only one project.

In Today screen and Project screen, projeqtor only shows the project he is assigned. However, when I click in the combobox in the upper left corner to "filter" a project, my entire project list is displayed (even the projects the user is not assigned to).

Attached, follows a print which shows the project screen with only one project, the project that the user is assigned (plus a template project), and the mentioned project list showing all projects (I'm not showing the project names, but you can see the list is big).

I noticed that this behavior had happened because I had previously accessed projeqtor with a user who was able to see all projects. Then, when the user with limited rights accessed projeqtor, this user with limited rights was able to see the complete project list (which I think is a access right issue). Once I clean the browser cache (SHIFT + F5), the user with limited access rights only sees its own projects in the list.

Would it be possible to force the cleaning of the cache (or something like that), so this access right issue would not happen?

PS: I'm using google chrome 37.0.2062.124 m (just in case this info matters).

Thank you very much indeed.
Attachments:
The topic has been locked.
More
11 Oct 2014 09:29 - 11 Oct 2014 09:29 #2 by babynus
Hi,

First, it is not a serious security issue, as you must have connected first with full visibility.
This means you have rights to see the full list :)

But you're right, this is quite a strange behavior.
Could you detail the way you disconnect / reconnect ?
Are you sure the user does not have some visibility to "all items on all projects" for one category of elements ? (it can be for meetings, for actions, ...)

Babynus
Administrator of ProjeQtOr web site
Last edit: 11 Oct 2014 09:29 by babynus.
The topic has been locked.
More
11 Oct 2014 15:32 #3 by francis2301
Hi,

Well, about the seriously of the issue, it may be somehow important if different users access the same machine (a shared machine, in a meeting room, for instance). But yes, probably this won't happen in a normal workstation. ;)

About the visibility and access rights, I have the following configuration:
1. I have a access mode called "controle total" where the user has total control for items on its own projects. (see attachment "access mode.png").
2. The user "francis.teste", with limited visibility, is configured with the profile "Equipe PMO" (PMO Member) - (see picture "User profile.png")
3. For the profile "Equipe PMO", in access mode to data screen, all items are configured with the access mode "controle total" (see pictures "access mode to data - 1/2/3.png"
4. For the profile "Equipe PMO", in specific access mode screen, all items are configured to see only items from its own projects (see pictures "specific access mode - 1/2.png"

So, having that configuration, I took the following steps:
1 - Connected in projeqtor with a user with full visibility to all items in all projects
2 - I used projeqtor with this user for a while, so I certainly click of the "project combobox" a few times, entered today and project screen and also other screens. (don't know exactly everything I did :unsure: )
3 - disconnected this user with full visibility.
4 - connected in projeqtor with the user with limited visibility (username "francis.teste", shown in the attachments).
5 - clicked on the "project combobox" and all projects were listed.
6 - I used projeqtor with this user for a while (user with limited visibility)
7 - disconnected from projeqtor.

I repeated steps 4 to 7, some times and always could see the entire list. So, after some trials, before connecting with the user "francis.test" (limited access), I hit "SHIFT + F5" to clean the browser cache. Then I connected again (Step 4) with the same user (francis.test) and in step 5, I only saw the project the user was assigned to.

Kind regards,
The topic has been locked.
More
11 Oct 2014 15:48 #4 by babynus
Hi,

I just tried, and could not reproduce :(

Connected as admin : list of project full
Disconnected
Connected as manager : list of project restricted to manager's project

So my question is "how do you disconnect" ?

Babynus
Administrator of ProjeQtOr web site
The topic has been locked.
More
07 Nov 2014 11:48 #5 by francis2301
Hi,
I do have to agree with you. I've been trying to reproduce the problem without success as well. After it has occurred the first time (and I've clean up the cache), it did not happen again, no matter what I do. :unsure: ;)

At that time, I have disconnected using the "disconnect" option in the bottom left corner of the system screen.

Thanks for your attention.
Kind Regards.
The topic has been locked.
Moderators: babynusprotion
Time to create page: 0.037 seconds

Cookies settings

×

Functional Cookies

Ce site utilise des cookies pour assurer son bon fonctionnement et ne peuvent pas être désactivés de nos systèmes. Nous ne les utilisons pas à des fins publicitaires. Si ces cookies sont bloqués, certaines parties du site ne pourront pas fonctionner.

Session

Please login to see yours activities!

Other cookies

Ce site web utilise un certain nombre de cookies pour gérer, par exemple, les sessions utilisateurs.