You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@continuum.apache.org by "Wendy Smoak (JIRA)" <ji...@codehaus.org> on 2008/09/25 07:08:48 UTC

[jira] Commented: (CONTINUUM-1889) Project group admin should not be able to move a project into a group he does not have access to

    [ http://jira.codehaus.org/browse/CONTINUUM-1889?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=148943#action_148943 ] 

Wendy Smoak commented on CONTINUUM-1889:
----------------------------------------

Emmanuel, does this actually prevent the move from taking place, or only the wrong projects from showing in the select list?

That is, could I still do it by constructing a url or form with the right values, and submitting it?


> Project group admin should not be able to move a project into a group he does not have access to
> ------------------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1889
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1889
>             Project: Continuum
>          Issue Type: Bug
>          Components: Project Grouping
>    Affects Versions: 1.2
>            Reporter: Wendy Smoak
>            Assignee: Emmanuel Venisse
>             Fix For: 1.2.1
>
>
> On the editProjectGroup.action page, a project group admin is allowed to move a project into _any_ other group, even if he does not have admin permissions there.
> The "Move to Group" drop downs should only contain groups for which the current user is an admin, and moves to other groups should be prevented.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira