OCSInventory-NG / OCSInventory-ocsreports

Webconsole for OCS Inventory NG
https://www.ocsinventory-ng.org
GNU General Public License v2.0
231 stars 151 forks source link

[BUG] Users with RO FIELD_RULE should not be allowed do delete Notes. #984

Open nwildner opened 4 years ago

nwildner commented 4 years ago

OCS Inventory version Version : 2.6

Describe the bug Users that are attached to a Read Only(RO) profile are able to delete Inventory notes.

To Reproduce Steps to reproduce the behavior:

  1. Create a CONEX_LDAP_CHECK_FIELD2_ROLE, set it to the default RO role.
  2. Login with a user that is attached to this role only.
  3. Try to Delete Notes from "Administrative Data" of any host that has.

Expected behavior Read-only users should not be able to alter/delete host data.

I know this could be a "FEATURE" cause it's a new permission but, in my opinion a Read Only profile should not be able to manage data in any level except if an additional permission overlaps the RO aspect of that main profile.

nwildner commented 4 years ago

"RO User can delete data"

"Not a bug. A feature".

LOL

charleneauger commented 4 years ago

Hi @nwildner ,

Sorry, feature label is a little bit excessive. However, We don't judged that issue as a bug because it isn't implemented on OCS. But not worry, we added your request on our RoadMap. I will label your issue as an "Enhancement", I think it's more appropriated. :-)

Regards, Charlene Auger

nwildner commented 4 years ago

Hi @nwildner ,

Sorry, feature label is a little bit excessive. However, We don't judged that issue as a bug because it isn't implemented on OCS. But not worry, we added your request on our RoadMap. I will label your issue as an "Enhancement", I think it's more appropriated. :-)

Regards, Charlene Auger

Seems fair :)

If you need any help i've recently updated our server to 2.7, and i can easily clone this VM to do some testing.

All the best.

nwildner commented 3 years ago

Quick update: same behavior after upgrading to 2.8