Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-31820

Roster 2 / students can view group memberships without having the 'viewgroup' permission

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 10.7, 11.2, 12.0 [Tentative]
    • Component/s: Roster2
    • Labels:
      None
    • Environment:
      10x/11x/trunk
    • 11 status:
      Resolved
    • 10 status:
      Resolved

      Description

      It seems if students do not have the viewgroup permission, they should not be able to see group memberships for anyone in the site.

      To reproduce
      1. Log in as a student when that role that does not have the roster.viewgroup permission
      2. Go to the Roster tool in a site with groups defined
      3. Click the Group Membership Link
      5. The student is able to see the group listings in the last column of the table

        Gliffy Diagrams

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  lcanessa Leonardo Canessa
                  Reporter:
                  drramsey Derek Ramsey
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  5 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Git Source Code