Skip to content

Users can see all objects via direct link despite having no READ permissions #2321

Closed
@ttemnikova

Description

@ttemnikova

Expected behavior

With the feature #2300 users have no access via a direct link to the objects for which they do not have READ or WRITE permissions. The user should get an appropriate error message (e.g. "You have no permissions to this object") instead

Actual behavior

The object is not in the list, but it is accessible via the direct link to the object

Steps to reproduce behavior

  1. user1 creates an object (concept set, cohort definition, characterization, pathways, incidence rates, PLE or PLP)
  2. user1 does not grant access to the object for any other user
  3. user2 try opening the object from the step 1 via a URL to the object

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions