View Issue Details

IDProjectCategoryView StatusLast Update
0023113mantisbtbugtrackerpublic2017-07-27 18:15
Reporterspacomp Assigned Toatrol  
PriorityhighSeveritymajorReproducibilityalways
Status closedResolutionno change required 
Product Version1.3.6 
Summary0023113: Getting "Access Denied" for Reporter while Assigning & Changing the Status of Issues
Description

We are in a process of migrating our existing Mantis instance [1.2.7] to 1.3.6

We have successfully carried out the same and fixed few issues post migration through Mantis Forum.

We are encountering a typical case wherein, the existing users with REPORTER level access are unable to ASSIGN and change STATUS of the issues,

We are getting "ACCESS DENIED" error while doing so.

I have looked into "config_defaults_inc.php" and also from application workflow interface, everything seems to be fine.

Note: The reason for opting the MantisBT version 1.3.6 was to stick to CLASSIC interface of Mantis, which our onsite team is well versed and we find it better as Functionality of Mantis being strongest aspect above all.

Steps To Reproduce

-

Additional Information

-

TagsNo tags attached.

Activities

atrol

atrol

2017-07-14 18:41

developer   ~0057228

to 1.3.6

I recommend to upgrade to 1.3.11 as there are major security issues in 1.3.6

We are encountering a typical case wherein, the existing users with REPORTER level access are unable to ASSIGN and change STATUS of the issues

This is the default behavior of Mantis

have looked into "config_defaults_inc.php"

I assume you mean config_inc.php?
You should provide the relevant information in it (the various treshold settings you might have set)

and also from application workflow interface

You should provide a screen shot of the page

spacomp

spacomp

2017-07-17 00:27

reporter   ~0057238

Atrol : I recommend to upgrade to 1.3.11 as there are major security issues in 1.3.6

SPACOMP : Is it possible to retain the classical theme [Interface] of the Mantis?

spacomp

spacomp

2017-07-17 00:32

reporter   ~0057239

Due to security restrictions, we are unable to upload / share the details, please bear with us.

Yes, "config_defaults_inc.php" is the file. We did compare with similar file from earlier instance of Mantis [Using Beyond Compare]. We have taken care to match to exact workflow as before.

atrol

atrol

2017-07-17 11:01

developer   ~0057243

Atrol : I recommend to upgrade to 1.3.11 as there are major security issues in 1.3.6
SPACOMP : Is it possible to retain the classical theme [Interface] of the Mantis

Maybe I don't understand the question.
1.3.6 and 1.3.11 come with an UI which is quite similar to what we had in 1.2.
Starting whith version 2.0 there is a complete new UI.

Yes, "config_defaults_inc.php" is the file.

You should never change this file as you might get issues when upgrading.
There is no need to change the file, as all changes can be done in config_inc.php
Changing source of Mantis is not supported, you have to check in a first step if the problems occurs when using the original source of Mantis.
The second step is to check if the problem occurs when using latest official build of the version you use, e.g. 1.3.11 at the moment if you use any older 1.3.x version.

Due to security restrictions, we are unable to upload / share the details

There is no way to provide support without having instructions how to reproduce the issue.

I recommend that you use a fresh install of 1.3.11. If the problem persists, do not hesitate to reopen the issue and provide detailed step-by-step instructions to reproduce the issue; the following additional information may also be useful:

  • Exact version of PHP, Database, Web server, Browser and Operating System

If the problem does not persist with a fresh install, you have to check the differences between the fresh install and your productive installation, check

  • Relevant customizations (e.g. changes in config_inc.php, settings in admin UI etc)
  • Installed plugins or custom functions ?
  • Was the MantisBT source code modified in any way ?
spacomp

spacomp

2017-07-17 23:51

reporter   ~0057250

Dear Atrol,

Thank you so much for the inputs that you gave, will rework afresh with 1.3.11.