View Issue Details

IDProjectCategoryView StatusLast Update
0013843mantisbtbugtrackerpublic2012-02-22 16:16
Reporternamao Assigned Toatrol  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionno change required 
Product Version1.2.8 
Summary0013843: Reporter-level users are able to open and view ALL the reports
Description

I'm not sure if other people are experiencing this but we are having a huge problem with permissions on our users. Report-level users are able to view ALL reports, even if they didn't report or if it's set to private. I've done a lot of modifications with the configuration but none have worked so far.

We need assistance on this as soon as possible as we don't want to have our other clients seeing the issues reported by other clients since some of them contain sensitive information.

TagsNo tags attached.

Activities

atrol

atrol

2012-02-04 03:44

developer   ~0031117

Check
a) that nobody changed setting $g_limit_reporters = ON;
b) that view status of your projects is set to "private"
c) the page "Workflow Thresholds" in row "Limit reporter's access to their own issues" where you can override setting $g_limit_reporters

namao

namao

2012-02-04 10:59

reporter   ~0031118

I think (c) resolved the issue. Thanks! ^^,

I have to ask, though:

Where can I find "$g_limit_reporters"?

Also, if I were to set the project to "private", would it not mean the project will not be available to users below developer-level?

atrol

atrol

2012-02-04 11:32

developer   ~0031119

Where can I find "$g_limit_reporters"?

the default (OFF) is set in config_defaults_inc.php
if you want to change it, you have to add your setting in config_inc.php

Also, if I were to set the project to "private", would it not mean the project will not be available to users below developer-level?

No, it will be available to administrators, managers of the private project and all other individual users which are assigned.

namao, as this is not a bug or feature request for MantisBT (you are asking for help on how to configure MantisBT) I am resolving this issue as "no change required".
Please use the forums, the help mailing list or IRC to get support on customising and using MantisBT.
http://www.mantisbt.org/support.php