Appian Community
Site
Search
Sign In/Register
Site
Search
User
DISCUSS
LEARN
SUCCESS
SUPPORT
Documentation
AppMarket
More
Cancel
I'm looking for ...
State
Not Answered
Replies
5 replies
Subscribers
6 subscribers
Views
2312 views
Users
0 members are here
Share
More
Cancel
Related Discussions
Home
»
Discussions
»
Process
Hi all, we found a privilege issues and don't know whether it is
eaglez
over 10 years ago
Hi all,
we found a privilege issues and don't know whether it is a expected behavior.
user in Group B can also accept the tempo task even if it is assigned to Group A, as long as he knows the task link.
OriginalPostID-144610
OriginalPostID-144610
Discussion posts and replies are publicly visible
0
Steve
over 10 years ago
Is it an administrative user?
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
0
sikhivahans
over 10 years ago
@eaglez If a basic user from one group tries to access the task from other group to which he doesn't belong the following error message will be seen:
"The requested task is not available.
You may not have permission to view the task, or it may have been deleted."
It would be worth checking the group memberships of the user who is able to access the task of other group by means of link explicitly.
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
0
eaglez
over 10 years ago
hi steveh, it is a basic user.
hi sikhivahans, i did check the group memberships.
the case here is :
we set the same email for all the test accounts and i'm in the email group. so i can recieve all new task notification email.
like the attached picture, the task is supposed to be assigned to another group " Client Manager".
however, i logged in as "IBG onboarding" which belongs to a different group and is just a basic user. i clicked the link in the email and can accept the task as "IBG onboarding".
this only happens in tempo. in portal app, it won't.
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
0
Chris
over 10 years ago
Note this may also be able to happen if the user has Manager permissions to the process model. In that scenario the user can access tasks assigned to other users (it is not listed in the documentation but should be AN-401222)
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
0
eaglez
over 10 years ago
thank you very much , csteward.
yes, it is the root cause. originally i didn't use "Manager permissions", but there was a weird issue and it seems "Manager permissions" could fix it.
anyway, thanks again.
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel