Uploaded image for project: 'Camunda Optimize'
  1. Camunda Optimize
  2. OPT-3010

Unauthorized report in combined report crashes Optimize

    XMLWordPrintable

    Details

    • Type: Bug Report
    • Status: Done
    • Priority: L3 - Default
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.7.0
    • Component/s: backend
    • Labels:
      None

      Description

      Problem description:

      • given
        • I create a combined report
        • I add report A and report B to the combined report
        • The user kermit has only access to report A (e.g. because he has only access to the definition key of report A or the tenants of report A)
      • when:
        • I log in with kermit and access the combined report
      • then:
        • I see an error message and I can't see the combined report at all
      • expected:
        • since kermit doesn't have access to all the reports in the combined report, he shouldn't be able to see the combined report at all
        • and even if kermit evaluates the combined report, he should get an error message that he's not authorized to evaluate the combined report because he doesn't have authorizations to see all the containing reports.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned
              Reporter:
              johannes.heinemann Johannes Heinemann
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: