Hi all, we found a privilege issues and don't know whether it is

Hi all,

we found a privilege issues and don't know whether it is a expected behavior.
user in Group B can also accept the tempo task even if it is assigned to Group A, as long as he knows the task link.

OriginalPostID-144610

OriginalPostID-144610

  Discussion posts and replies are publicly visible

Parents
  • hi steveh, it is a basic user.

    hi sikhivahans, i did check the group memberships.
    the case here is :
    we set the same email for all the test accounts and i'm in the email group. so i can recieve all new task notification email.
    like the attached picture, the task is supposed to be assigned to another group " Client Manager".
    however, i logged in as "IBG onboarding" which belongs to a different group and is just a basic user. i clicked the link in the email and can accept the task as "IBG onboarding".

    this only happens in tempo. in portal app, it won't.

Reply
  • hi steveh, it is a basic user.

    hi sikhivahans, i did check the group memberships.
    the case here is :
    we set the same email for all the test accounts and i'm in the email group. so i can recieve all new task notification email.
    like the attached picture, the task is supposed to be assigned to another group " Client Manager".
    however, i logged in as "IBG onboarding" which belongs to a different group and is just a basic user. i clicked the link in the email and can accept the task as "IBG onboarding".

    this only happens in tempo. in portal app, it won't.

Children
No Data