[ 
https://issues.apache.org/jira/browse/OFBIZ-7741?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15457796#comment-15457796
 ] 

Taher Alkhateeb commented on OFBIZ-7741:
----------------------------------------

I believe this should be minor or trivial.. Definitely not critical

> Address scope peculiarities within search/find functionality of projectmgr
> --------------------------------------------------------------------------
>
>                 Key: OFBIZ-7741
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-7741
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: specialpurpose/projectmgr
>            Reporter: Pierre Smits
>            Priority: Critical
>
> Currently the search/find functions in the projectmgr component also 
> retrieves projects a user is not a participant in. This is especially 
> critical regarding projects with scope 'WES_PRIVATE - private' or 
> 'WES_CONFIDENTIAL - confidential'.
> These project may only be search for/found by users that are exlicit 
> participants of the projects. This over ruless the generic permissions of 
> 'PROJECTMGR_ADMIN' or 'PROJECTMGR_VIEW'.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to