View Issue Details

IDProjectCategoryView StatusLast Update
0008439mantisbtemailpublic2015-03-19 04:46
ReporterCADbloke Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
Platformany 
Product Version1.1.0a4 
Summary0008439: email to reporter on admin update includes related task that reporter is not authorised to see
Description

Updated a ticket in an unrestricted project to be a child of another issue in a private project, inaccessible to the reporter of the updated ticket.

Email to reporter included relationship summary and "child of" and the issue number of the issue they don't have access to.

Note - the user cannot access the issue but they are aware of the presence of another issue which they don't have access to.

Not a deal breaker for me.

Steps To Reproduce
  1. Report issue as a reporter.
  2. Admin relates reported issue to an issue that reporter does not have access to.
  3. Auto email includes relationship change
Additional Information

Probably need to add code to email sending module to verify that recipient has rights to the information they are getting. This could only be implemented if Mantis sends individual emails to each recipient for an incident / update.

TagsNo tags attached.

Activities

There are no notes attached to this issue.