osbornm / AZtoGH

0 stars 0 forks source link

Activity History - Inconsitent Permissions for Server Admin User #458

Open osbornm opened 11 years ago

osbornm commented 11 years ago

Log into Control Portal as a user who only has Server Admin permissions (or any role other than Account Admin). Note the Recent Activity list on the Dashboard.

Expected: User can see recent history for all servers. User can click "activity history" link to view full history for all servers.

Actual: Recent history entries include user management events (user created, roles updated, etc.) which is something a server admin should not be aware of. Clicking on "activity history" link results in "Unathorized - You don't have permissions to view this resouce." A Server Admin can go see recent server history on the Servers top level page, however currently they cannot see the full history for all servers.

Either don't show recent history on the dashboard or filter it appropriately. Either don't show a link to the activity history page, or enable it for the role but make sure to filter the data appropriately. Without the fully functional history page, server admins can't see the full history.

Created From: https://agilezen.com/project/48813/story/369