View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0013843 | mantisbt | bugtracker | public | 2012-02-04 02:18 | 2012-02-22 16:16 |
| Reporter | namao | Assigned To | atrol | ||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | closed | Resolution | no change required | ||
| Product Version | 1.2.8 | ||||
| Summary | 0013843: Reporter-level users are able to open and view ALL the reports | ||||
| Description | I'm not sure if other people are experiencing this but we are having a huge problem with permissions on our users. Report-level users are able to view ALL reports, even if they didn't report or if it's set to private. I've done a lot of modifications with the configuration but none have worked so far. We need assistance on this as soon as possible as we don't want to have our other clients seeing the issues reported by other clients since some of them contain sensitive information. | ||||
| Tags | No tags attached. | ||||
|
Check |
|
|
I think (c) resolved the issue. Thanks! ^^, I have to ask, though: Where can I find "$g_limit_reporters"? Also, if I were to set the project to "private", would it not mean the project will not be available to users below developer-level? |
|
the default (OFF) is set in config_defaults_inc.php
No, it will be available to administrators, managers of the private project and all other individual users which are assigned. namao, as this is not a bug or feature request for MantisBT (you are asking for help on how to configure MantisBT) I am resolving this issue as "no change required". |
|