[JIRA] [core] (JENKINS-18633) User with the right READ is able to change main server description

2013-07-24 Thread r...@orange.fr (JIRA)















































Raphael CHAUMIER
 assigned  JENKINS-18633 to Raphael CHAUMIER



User with the right READ is able to change main server description
















Change By:


Raphael CHAUMIER
(24/Jul/13 11:42 AM)




Assignee:


RaphaelCHAUMIER



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.




[JIRA] [core] (JENKINS-18633) User with the right READ is able to change main server description

2013-07-05 Thread ds....@nxmail.de (JIRA)














































Dominik Schwald
 created  JENKINS-18633


User with the right READ is able to change main server description















Issue Type:


Bug



Affects Versions:


current



Assignee:


Unassigned


Components:


core



Created:


05/Jul/13 11:57 AM



Description:


I have a user that has only the single right "Job: read", but is still allowed to change the description of the server (main heading) for everyone. 

Could be reproduced: 

	log on as this user


	main page shows up, but no link to change the description)


	click on "my views"


	this will open the URL https://SERVERNAME/me/my-views
which is redirected to https://SERVERNAME/me/my-views/view/Alle/
	On this page the global server description is writeable



This could also be tested by directly opening the URL: 
https://SERVERNAME/me/my-views/editDescription





Environment:


Windows7 using the integrated webserver using ActiveDirectory authentication and matrix based security.




Project:


Jenkins



Priority:


Minor



Reporter:


Dominik Schwald

























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.




[JIRA] [core] (JENKINS-18633) User with the right READ is able to change main server description

2013-07-05 Thread ds....@nxmail.de (JIRA)














































Dominik Schwald
 updated  JENKINS-18633


User with the right READ is able to change main server description
















edit: fixed markup





Change By:


Dominik Schwald
(05/Jul/13 12:02 PM)




Description:


IhaveauserthathasonlythesinglerightJob:read,butisstillallowedtochangethedescriptionoftheserver(mainheading)foreveryone.Couldbereproduced:
-
*
logonasthisuser*
*
mainpageshowsup,butnolinktochangethedescription)
-
*
clickonmyviews*
*
thiswillopentheURLhttps://SERVERNAME/me/my-views
**
whichisredirectedtohttps://SERVERNAME/me/my-views/view/Alle/*
*
OnthispagetheglobalserverdescriptioniswriteableThiscouldalsobetestedbydirectlyopeningtheURL:https://SERVERNAME/me/my-views/editDescription



























This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira







-- 
You received this message because you are subscribed to the Google Groups Jenkins Issues group.
To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-issues+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.