While experimenting with permissions, I found that if I have no permissions to 
a process group, but do have permissions to a child that lives in that group, I 
can move that child around on the UI.

I know that in the object model the x,y position values are part of the child, 
which I have access to; but in this scenario it feels like I'm allowed to 
modify things in a group where I have no permissions. I propose that users 
can't move (x,y) objects if they do not have modify access to the parent group. 
Thoughts?

--Peter

Reply via email to