Uploaded image for project: 'Camunda Optimize'
  1. Camunda Optimize
  2. OPT-3013

Unauthorized user can share dashboard to see unauthorized combined reports

    XMLWordPrintable

    Details

    • Type: Bug Report
    • Status: Done
    • Priority: L3 - Default
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.7.0
    • Component/s: backend
    • Labels:
      None

      Description

      Scenario

      • User A shares his collection with user B as viewer
      • The collection contains a dashboard with a combined report which contains a single report for that user B has no authorization

      Steps to reproduce

      • open the dashboard with user B
      • user the share function and open the link in a new browser

      Problem
      the shared link shows the combined report without restriction

      Expected behavior
      User B is not able to share the dashboard link

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              michael.schoettes Michael Schoettes
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: