View Issue Details

IDProjectCategoryView StatusLast Update
0007392mantisbtsecuritypublic2007-05-08 03:43
Reporterurkle Assigned Tovboctor  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionduplicate 
Product Version1.0.5 
Summary0007392: a manager of a project can add other users to the project w/ administrative rights
Description

when user demo1 has Manager access to projectA, he can log in, switch to projectA and grant rights to other users in the system for that project.. However he can grant rights higher than what he has. ie. he can give another user administrative rights to projectA.

Additional Information

Shouldn't a user only be able to grant access to as high as he already has? ie.. a manager can grant manager and lower?

TagsNo tags attached.

Relationships

duplicate of 0006719 closedvboctor Manager of a project can assign the Administrator role to a user. 

Activities

There are no notes attached to this issue.