Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-9843

A user can see variables in Tasklist even that they are not supposed to

    XMLWordPrintable

    Details

    • Type: Bug Report
    • Status: Closed
    • Priority: L3 - Default
    • Resolution: Fixed
    • Affects Version/s: 7.11.0-alpha2
    • Fix Version/s: 7.11.0, 7.11.0-alpha3
    • Component/s: engine
    • Labels:
      None

      Description

      Given:

      • process engine configuration introduced in CAM-9591 is enabled - ProcessEngineConfiguration#enforceSpecificVariablePermission
      • user does not have permissions to see variables - no READ_*_VARIABLE
      • filter defines variables

      Observed Behavior:

      • user can see variables in Tasklist (in the list of tasks)

      Expected Behavior:

      • user cannot see variables in Tasklist (in the list of tasks)

      Hints:
      Currently, the authorization check is disabled for this query, please have a look at CAM-6082

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              michael.schoettes Michael Schoettes
              Reporter:
              yana.vasileva Yana Vasileva
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: