#388: Test environment isolation across product boundaries - after #355
---------------------------+--------------------------------------------
  Reporter:  olemis        |      Owner:  rjollos
      Type:  task          |     Status:  review
  Priority:  critical      |  Milestone:  Release 8
 Component:  multiproduct  |    Version:
Resolution:                |   Keywords:  product environment testing QA
---------------------------+--------------------------------------------

Comment (by olemis):

 Replying to [comment:8 rjollos]:
 [...]
 >
 > A related issue is that, since `process_request` is checking for
 `TICKET_CREATE` permission, the user must have `TICKET_CREATE` for their
 current scope in order to use the QCT.
 >

 this is by design , if creating a ticket via QCT user must be granted with
 TICKET_CREATE in both the active env and the target env . The former case
 is not a big deal since
 
[source:trunk/bloodhound_theme/bhtheme/templates/bloodhound_theme.html@1553998:339-356
 QCT form is not displayed] . Nevertheless it must still be asserted in
 code to be consistent in case of direct requests hijacking system logic .

 [...]

-- 
Ticket URL: <https://issues.apache.org/bloodhound/ticket/388#comment:9>
Apache Bloodhound <https://issues.apache.org/bloodhound/>
The Apache Bloodhound issue tracker

Reply via email to