Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Group History does not respect group security #5043

Closed
1 task done
azturner opened this issue Jun 20, 2022 · 1 comment
Closed
1 task done

Group History does not respect group security #5043

azturner opened this issue Jun 20, 2022 · 1 comment
Labels
Status: Confirmed It's clear what the subject of the issue is about, and what the resolution should be. Type: Bug Confirmed bugs or reports that are very likely to be bugs. x-Fixed in v13.7

Comments

@azturner
Copy link
Contributor

azturner commented Jun 20, 2022

Prerequisites

Description

The Group History block shows groups even though current person does not have view access to that group. In screenshot below, Ted Decker does not have view access to the "Abuse Care" group. The Group List block correctly does not show that group, but the group history block does:

image

Ted can also see in Jenny's history when she was added to that group:

image

Steps to Reproduce

  1. Create/Edit group (using group type configured for history) and secure so not all people can view the group
  2. Add someone to that group.
  3. Run the Process Group History job
  4. Log in as someone who should not be able to view the group and view the group tab on the profile of person added to group.

Expected behavior:

User is not able to see anything related to the group they do not have View access to.

Actual behavior:

The person can see the group in the group history chart and in the person's history.

Versions

  • Rock Version: v13.3
  • Client Culture Setting: en-US
@azturner azturner changed the title Group History does not respect group history Group History does not respect group security Jun 20, 2022
@leahjennings leahjennings added Type: Bug Confirmed bugs or reports that are very likely to be bugs. Status: Confirmed It's clear what the subject of the issue is about, and what the resolution should be. labels Jun 21, 2022
@azturner
Copy link
Contributor Author

@ethan-sparkdevnetwork, this is marked as fixed in v13.7, but I'm not sure the commit is in that branch. Will it be included in 13.7?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: Confirmed It's clear what the subject of the issue is about, and what the resolution should be. Type: Bug Confirmed bugs or reports that are very likely to be bugs. x-Fixed in v13.7
Projects
None yet
Development

No branches or pull requests

3 participants