bcgov / entity

ServiceBC Registry Team working on Legal Entities
Apache License 2.0
23 stars 58 forks source link

NR UI: staff cannot open user's NR #8187

Open severinbeauvais opened 3 years ago

severinbeauvais commented 3 years ago

I am not sure if this is a requirement or even desired, but I expected this would work (ie, same as the other Entity UIs) and it doesn't.

As a staff user, When I am logged in to the BCROS domain And I try to load a NR using its "paid URL" Then I expect the NR to load and display So that I can see the same thing the user is seeing.

Instead I get a 403 (Forbidden) error.

Sample paid URL: https://dev.bcregistry.ca//namerequest/nr/2262379/?paymentId=1335&status=UEFZTUVOVF9DQU5DRUxMRUQ%3D

Workaround: load the NR using the NR number and the user's email address or phone number for authentication.

severinbeauvais commented 3 years ago

This needs to be verified. For whatever reason, I could not access the sample NR using ANY login this morning. Perhaps some session storage keys were not set correctly.

But anyway, the login question should be considered. (And also, possibly, whether a logged in user can access their NRs without entering the NR number and their email/phone?)