? Pending

User tests: Successful: Unsuccessful:

avatar brianteeman
brianteeman
31 Aug 2018

All the modules in the admin control panel have a cog icon which lets you edit the module. Howeveer the permission check is not correct as you need to have access to the module component AND to edit the module.

To test

Create a user with default manager permissions
Create a user with default administrator permissions
Change the permissions on one module so that only Super Users can edit the module

Login as manager - the cog is displayed on all the modules but you get a 403
Login as administrator - the cog is displayed and works on all the modules except the one you dont have permission to edit where you get a 403
Login as super user - the cog is displayed and works on all the modules

Apply the pr

Login as manager - the cog is not displayed at all
Login as administrator - the cog is displayed and works on all the modules except the one you dont have permission to edit where the cog is not displayed at all
Login as super user - the cog is displayed and works on all the modules

this is a redo of #20967 where I couldnt resolve the conflicts due to the composer changes etc

avatar brianteeman brianteeman - open - 31 Aug 2018
avatar brianteeman brianteeman - change - 31 Aug 2018
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 31 Aug 2018
Category Administration Templates (admin)
avatar wilsonge wilsonge - change - 31 Aug 2018
Status Pending Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2018-08-31 21:42:28
Closed_By wilsonge
Labels Added: ?
avatar wilsonge wilsonge - close - 31 Aug 2018
avatar wilsonge wilsonge - merge - 31 Aug 2018
avatar wilsonge
wilsonge - comment - 31 Aug 2018

Thanks!

avatar brianteeman
brianteeman - comment - 31 Aug 2018

thanks - makes the next stage easier

Add a Comment

Login with GitHub to post a comment