Able to see issues in "Your work" page although permission is not granted

XMLWordPrintable

    • 1
    • Severity 2 - Major

      Issue Summary

      In the "Your work" page under the "Worked on tab", users can still see the issues they've worked on previously although they don't have access to it.

      Steps to Reproduce

      1. Add a user to a group A
      2. Grant group A to view project A
      3. Get the user to create a test issue, comment on issue edit to fill in the "Worked on" page
      4. Remove the user from group A
      5. Try to access project A, you won't be able to.
      6. But when the user visits "Your work" page, under the "Worked on" tab, the user can still see the issue summary 

      Expected Results

      Users should not be able to see any information regarding issues for projects they do not have access to.

      Actual Results

      Users can actually see the Issue summary, issue type. etc
      But they cannot access it if they click on the issue

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

        1. Screenshot 2.PNG
          Screenshot 2.PNG
          38 kB
        2. Screenshot 1.PNG
          Screenshot 1.PNG
          15 kB

            Assignee:
            Gonçalo Cardoso
            Reporter:
            Adam (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: