Project

General

Profile

Bug #7311

Everybody can edit marks

Added by Evgeny Novikov over 3 years ago. Updated over 3 years ago.

Status:
Rejected
Priority:
High
Assignee:
-
Category:
Bridge
Target version:
-
Start date:
06/20/2016
Due date:
% Done:

0%

Estimated time:
Detected in build:
svn
Platform:
Published in build:

Description

Even users without any noticeable rights (I just registered a new user and signed in on behalf on it) can edit likely any marks. May be this is a consequence of some bug or incorrectly interfered settings for jobs or/and users.

History

#1

Updated by Vladimir Gratinskiy over 3 years ago

  • Status changed from New to Feedback

Why I can't set "Rejected" status?

There is not bugs. I think you met this scenario:
1) Somebody create job and set "Global role" to "Expert" or "Expert and operator".
2) He solve the job and mark its unsafes.

All marks can be modified by all users (they are experts for this job) before the job will be deleted.

#2

Updated by Evgeny Novikov over 3 years ago

  • Status changed from Feedback to Rejected
  • Assignee deleted (Vladimir Gratinskiy)

Vladimir Gratinskiy wrote:

Why I can't set "Rejected" status?

I will open a feature request to administrators. This does look strange.

There is not bugs. I think you met this scenario:
1) Somebody create job and set "Global role" to "Expert" or "Expert and operator".
2) He solve the job and mark its unsafes.

All marks can be modified by all users (they are experts for this job) before the job will be deleted.

Yes this looks so. But it isn't trivial to catch. Are there any obstacles to put a link to a job on which a given mark was based on if so? The job can be unreached through associated reports if corresponding associations are broken or disappear after some changes in reports or marks. I will open a separate feature request for this.

Also available in: Atom PDF