Uploaded image for project: 'ui-users'
  1. ui-users
  2. UIU-174

User with "Users: Can view user profile" can edit address

    XMLWordPrintable

Details

    Description

      Overview: When testing UIU-154, it was discovered that the user assigned the permission "Users. Can view user profile" had some edit rights.

      Steps to repro:
      1. Log-in to FOLIO test as diku_admin
      2. Assign to a given user A the permission "User. Can view user profile"
      3. Log-out and login as the given user A.
      4. The user has access to the User app in the top navigation bar
      5. Click on the User app, and select a random user B.

      Expected results:
      Only able to view the detail page for user B.

      Actual results:
      I looks like user A with the permission "Users. Can view user profile" can edit the address on user B's detail page. Can edit the address data elements, but when saving the changes, then an error message pop up.

      Additional info: See the two screen dumps.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                mike Mike Taylor
                charlotte Charlotte Whitt
                Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  Time Tracking

                    Estimated:
                    Original Estimate - Not Specified
                    Not Specified
                    Remaining:
                    Time Spent - 1 hour, 30 minutes Remaining Estimate - 45 minutes
                    45m
                    Logged:
                    Time Spent - 1 hour, 30 minutes Remaining Estimate - 45 minutes
                    1h 30m

                    TestRail: Runs

                      TestRail: Cases