You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@continuum.apache.org by "Piotr Krzysztoporski (JIRA)" <ji...@codehaus.org> on 2008/10/06 11:33:08 UTC

[jira] Created: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

'Project Developer' role has rights to delete project group to which he is assign to.
-------------------------------------------------------------------------------------

                 Key: CONTINUUM-1919
                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
             Project: Continuum
          Issue Type: Bug
          Components: Security
    Affects Versions: 1.2
            Reporter: Piotr Krzysztoporski


Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Assigned: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Maria Catherine Tan (JIRA)" <ji...@codehaus.org>.
     [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Maria Catherine Tan reassigned CONTINUUM-1919:
----------------------------------------------

    Assignee: Maria Catherine Tan

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>         Attachments: continuum-1919-continuum-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Commented: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Maria Catherine Tan (JIRA)" <ji...@codehaus.org>.
    [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=150268#action_150268 ] 

Maria Catherine Tan commented on CONTINUUM-1919:
------------------------------------------------

There's a bug with this patch.

As a project group administrator: 
I can still delete all project groups.  (Ok)

As a project group developer:  
I can no longer delete a project group.  (OK)

As a project administrator of a certain resource: 
I can no longer delete the project group even if I have a project admin role for that group. (BUG)

As a project developer of a certain resource:
I can no longer delete that group. (OK)

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>         Attachments: continuum-1919-continuum-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Updated: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Emmanuel Venisse (JIRA)" <ji...@codehaus.org>.
     [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Emmanuel Venisse updated CONTINUUM-1919:
----------------------------------------

    Fix Version/s: 1.2.1

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>             Fix For: 1.2.1
>
>         Attachments: continuum-1919-continuum-security.patch, continuum-1919-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Updated: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Jevica Arianne B. Zurbano (JIRA)" <ji...@codehaus.org>.
     [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Jevica Arianne B. Zurbano updated CONTINUUM-1919:
-------------------------------------------------

    Attachment: continuum-1919-continuum-security.patch

Attached patch.
- removed the delete project group right of a Project Developer

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>         Attachments: continuum-1919-continuum-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Commented: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Maria Catherine Tan (JIRA)" <ji...@codehaus.org>.
    [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=150269#action_150269 ] 

Maria Catherine Tan commented on CONTINUUM-1919:
------------------------------------------------

Maybe you could move the "continuum-remove-group" permission under the project-administrator template instead :-)

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>         Attachments: continuum-1919-continuum-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Closed: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Maria Catherine Tan (JIRA)" <ji...@codehaus.org>.
     [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Maria Catherine Tan closed CONTINUUM-1919.
------------------------------------------

    Resolution: Fixed

Fixed in revision 703287. Thanks!

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>         Attachments: continuum-1919-continuum-security.patch, continuum-1919-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] Updated: (CONTINUUM-1919) 'Project Developer' role has rights to delete project group to which he is assign to.

Posted by "Jevica Arianne B. Zurbano (JIRA)" <ji...@codehaus.org>.
     [ http://jira.codehaus.org/browse/CONTINUUM-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Jevica Arianne B. Zurbano updated CONTINUUM-1919:
-------------------------------------------------

    Attachment: continuum-1919-security.patch

continuum-1919-security.patch: "continuum-remove-group" permission moved to Project Administrator template.

Thanks!:)

> 'Project Developer' role has rights to delete project group to which he is assign to.
> -------------------------------------------------------------------------------------
>
>                 Key: CONTINUUM-1919
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-1919
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.2
>            Reporter: Piotr Krzysztoporski
>            Assignee: Maria Catherine Tan
>         Attachments: continuum-1919-continuum-security.patch, continuum-1919-security.patch
>
>
> Developer should be able to delete projects from the group, but not the group itself.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira