Project group admin should not be able to grant system-wide roles to himself
----------------------------------------------------------------------------

                 Key: CONTINUUM-1867
                 URL: http://jira.codehaus.org/browse/CONTINUUM-1867
             Project: Continuum
          Issue Type: Bug
          Components: Web - Security
    Affects Versions: 1.2.0
            Reporter: Wendy Smoak


As a project group admin for a single group, I am able to edit my user account 
and grant any role up to and including system administrator.

A project group admin should be able to grant the roles for his own project 
group to other users.  He should not be able to elevate his own permissions.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to