-
Bug
-
Resolution: Fixed
-
Medium
-
11.6.0
-
Severity 3 - Minor
-
No
Issue Summary
When accessing the Epics/Capabilities Recycle/Cancel bin, the user can select "All Programs" to display the items that were deleted/canceled, even those that the user is not a member. This allows the user to restore/delete items that should not be visible to them at all.
Steps to Reproduce
- With a User that is part of only one Program, and has access to the bins, go to the recycle bin
- Now select "Select ALL" for Program and PI
- See how the list will include all deleted items, even the ones the user is not part of the Portfolio/Program
- And how he can restore/delete any of them
Expected Results
Recycle/Cancel bin would follow the same logic that the grids use for access to items.
Actual Results
Recycle/Cancel bin doesn't apply the logic of being a member of a Portfolio/Program to see items.
Workaround
Currently, there is no known workaround for this behavior. A workaround will be added here when available
- is related to
-
JIRAALIGN-5984 Feature Recycle/Cancel bin: any user with access to the bin can see all the items on it
-
- Closed
-