[Instruments] Site/Project permission issues #6880
Labels
Category: Bug
PR or issue that aims to report or fix a bug
Category: Security
PR or issue that aims to improve security
Users can have access to candidates' information they don't have permission to access if they have the direct link.
(ex: /instruments/aosi/?candID=300258&sessionID=1578&commentID=DDE_300258OTT2581578261524668110)
To reproduce
Click here for breakdown per participant
orClick here for breakdown per participant
Closely related to #6934
The text was updated successfully, but these errors were encountered: