Bug (done?)

Rights to View / Display/#7233

Summary

done?
Nov 28, 2008
100%
Nov 29, 2008 / guest
Jan 14, 2009 / pixtur
pixtur
 

Attached files

No files uploaded
 
This task does not have any text yet.
Doubleclick here to add some.

Issue report

Major
Always
Apache/1.3.36 Server, PHP5
08093RC1
2008-11-15
Doesn't matter if you are a client, or a member. You can view the other person's tasks (from all different projects) without permission to.

All you have to do, is login into the system, on the right side where the member list is, click on that.

You will be brought to the overview screen of that user. Click on the "Tasks" / "Efforts" button at the top and you can view that user's task (just the subject - not the details) from all projects.

When a client sees this, he or she will know how much tasks you have in other projects, and what if you wanted a project that is hidden from someone else? YOu cant, cause it will be transparent here if you have tasks in other projects.

Although it restricts you from viewing the details, it has a list.
Basically someone can view all your tasks and efforts from other projects, but they can't click into it, they can just see the "Name / Subject".
Make it hidden just like the Projects and Changes tab do.
 

2 Comments

guest:Ohhhh, this is a serious problem

4 years ago - Delete

I hope that non of my clients has seen this...
(I have some tasks like "Get rid of client XY"...)

gb5256

pixtur:should be fixed

4 years ago