Can still edit profiles with Users Permission: Can view user profile

Description

The following two tests ahould only have permissions to view Users.
https://foliotest.testrail.io/index.php?/tests/view/10788
https://foliotest.testrail.io/index.php?/tests/view/11024

When I follow the steps in the test cases, I can still edit the user details. I have emptied Google Chrome cache several times.

CSP Request Details

None

CSP Rejection Details

None

Potential Workaround

None

Attachments

2

Checklist

hide

TestRail: Results

Activity

Show:

Julian Ladisch December 19, 2019 at 10:24 PM

Two issues haven been raised. They need to be handled separately. Therefore I split this into two issues:


I close this issue in favor of the other two.

Martin Spenger December 19, 2019 at 2:41 PM

And if I only have the permission "Users: Can view user profile", I have the option to see and use the "Edit"-button (see screenshot). Maybe it would be helpful to remove the button or have fields, that are not editable.

Martin Spenger December 19, 2019 at 2:34 PM
Edited

Hi ,

in a test case, I had a user with only two permission:
1) Users: Can assign and unassign service points to users
2) Users: Can view user profile

However, I was able to edit all other Information, e.g. telephone number, and save the changes.

Julian Ladisch December 19, 2019 at 2:20 PM

https://foliotest.testrail.io requires a login I don't have.

After creating a user that has only the single permission "Users: Can view user profile" I can login with that user and view all users. I can also open the edit view and change some values. But when trying to save the changes this is blocked with this error message:
"ERROR: in module @folio/users, operation PUT on resource 'selUser' failed, saying: Access requires permission: users.item.put"

Is this bug report about opening the edit screen or about successfully saving changed values?

If the latter please post a complete list of all permissions assigned; the sceenshot only shows a few.

Cate Boerema December 18, 2019 at 9:44 AM

Hi I see you assigned this to Vega. Were you planning on trying to get it fixed for Q4? It is a regression (I checked Chalmers' environment). Chalmers has one permission set that includes "Can view user profile" so it would be great if we could get this permission working again. Not sure if it's a release blocker, though (we'd need to check with Chalmers if we really think this isn't feasible to fix.).

Duplicate

Details

Assignee

Reporter

Priority

Development Team

Prokopovych

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created December 17, 2019 at 1:47 PM
Updated August 12, 2020 at 6:22 PM
Resolved December 19, 2019 at 10:24 PM
TestRail: Cases
TestRail: Runs