EBMS Tickets

Issue Number 429
Summary Users without any role are able to modify data
Created 2017-04-13 11:38:06
Issue Type Bug
Submitted By Kline, Bob (NIH/NCI) [C]
Assigned To Kline, Bob (NIH/NCI) [C]
Status Closed
Resolved 2017-06-07 12:30:58
Resolution Fixed
Path /home/bkline/backups/jira/oceebms/issue.206489

Kevin was able to navigate to one or more pages using an account which had been assigned no EBMS roles and modify packet data. Need to find out more about which pages were involved. Also need to go through the entire system and make sure roles are checked for access to every page.

Comment entered 2017-06-07 12:30:58 by Kline, Bob (NIH/NCI) [C]

Implemented on DEV. I'll have Kevin test this one.

Comment entered 2017-06-07 14:21:23 by Kline, Bob (NIH/NCI) [C]

Kevin has also successfully tested the solution.

Elapsed: 0:00:00.000845