Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Instruments] Site/Project permission issues #6880

Open
laemtl opened this issue Aug 3, 2020 · 0 comments
Open

[Instruments] Site/Project permission issues #6880

laemtl opened this issue Aug 3, 2020 · 0 comments
Assignees
Labels
Category: Bug PR or issue that aims to report or fix a bug Category: Security PR or issue that aims to improve security

Comments

@laemtl
Copy link
Contributor

laemtl commented Aug 3, 2020

Users can have access to candidates' information they don't have permission to access if they have the direct link.
(ex: /instruments/aosi/?candID=300258&sessionID=1578&commentID=DDE_300258OTT2581578261524668110)

To reproduce

  • Login with the admin user, go to Reports > Statistics > Behavioural
  • Click Click here for breakdown per participant or Click here for breakdown per participant
  • Click on a candidate from a particular site/project and save the url
  • Login with another user with no permission for that particular site/project
  • User can see the page

Closely related to #6934

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Category: Bug PR or issue that aims to report or fix a bug Category: Security PR or issue that aims to improve security
Projects
None yet
Development

No branches or pull requests

2 participants