-
Bug Report
-
Resolution: Fixed
-
L3 - Default
-
3.1.0, 3.2.0
-
Not defined
Context:
According to our documentation, users require READ permissions to see other users/groups in Optimize and be able to e.g. add them to collections. However, currently, you require ALL permissions to do this. If a user only has read permission, they cannot see others or add them to a collection.
Relevant docs: https://docs.camunda.org/optimize/latest/technical-guide/setup/authorization/#user-and-group-related-authorizations
AT:
- Users can see other users/groups even when they "only" have read permissions for the relevant resource
- Users can add other users/groups to collections even when they "only" have read permissions for this resource
- Add IT that checks that this works with read permission (current IT always gives all permissions)