#388: Test environment isolation across product boundaries - after #355
---------------------------+--------------------------------------------
Reporter: olemis | Owner: rjollos
Type: task | Status: review
Priority: critical | Milestone: Release 8
Component: multiproduct | Version:
Resolution: | Keywords: product environment testing QA
---------------------------+--------------------------------------------
Comment (by olemis):
Replying to [comment:8 rjollos]:
[...]
>
> A related issue is that, since `process_request` is checking for
`TICKET_CREATE` permission, the user must have `TICKET_CREATE` for their
current scope in order to use the QCT.
>
this is by design , if creating a ticket via QCT user must be granted with
TICKET_CREATE in both the active env and the target env . The former case
is not a big deal since
[source:trunk/bloodhound_theme/bhtheme/templates/bloodhound_theme.html@1553998:339-356
QCT form is not displayed] . Nevertheless it must still be asserted in
code to be consistent in case of direct requests hijacking system logic .
[...]
--
Ticket URL: <https://issues.apache.org/bloodhound/ticket/388#comment:9>
Apache Bloodhound <https://issues.apache.org/bloodhound/>
The Apache Bloodhound issue tracker