GemsTracker / gemstracker-library

GEneric Medical Survey Tracker, main library
http://gemstracker.org
BSD 3-Clause "New" or "Revised" License
6 stars 2 forks source link

Inappropriate access for some track pages #643

Closed mddejong closed 3 years ago

mddejong commented 3 years ago

Some track level items allow cross-organizational access where this is not appropriate.

This is solved in 1.9.1 and is only an issue for multi-org sites. In general the access reveals little beyond the participation of the patient in another organization.

It may be appropriate to back-port the fix to previous versions, though some testing that the fix does not break other code is needed in advance,