Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plan Collaborators With "Read only" Permissions Are Still Able to Add Contributors to a Plan #3439

Open
aaronskiba opened this issue Jul 22, 2024 · 4 comments

Comments

@aaronskiba
Copy link
Contributor

aaronskiba commented Jul 22, 2024

Please complete the following fields as applicable:

What version of the DMPRoadmap code are you running? (e.g. v2.2.0)
v4.2.0

Expected behaviour:

  • I'm not 100% sure. However, I'd assume that collaborators with "read only" access on a plan shouldn't be able to modify it in any way.

Actual behaviour:

  • Plan collaborators with "read only" can successfully add a contributor to a plan.
    Steps to reproduce:

    1. Add a collaborator and give them "read only" access
  • Screenshot from 2024-07-22 10-05-14

    1. Sign into the app as the added "read only" user and navigate to the corresponding plan
  • Screenshot from 2024-07-22 10-06-06

    1. Try adding a contributor to the plan
  • Screenshot from 2024-07-22 10-06-16

  • Screenshot from 2024-07-22 10-06-49

@aaronskiba
Copy link
Contributor Author

@martaribeiro is this in fact unwanted behaviour?

@johnpinto1
Copy link
Contributor

@aaronskiba This looks like a bug.

@martaribeiro
Copy link
Contributor

I think it was @briri who added this feature to Roadmap. Maybe he had a reason to allow a "read only" user to add a contributor to a plan.
I asked Diana and Magdalena to see if there was a reason for this. We are not sure either. To me looks like a bug as John said.

@briri
Copy link
Contributor

briri commented Jul 29, 2024

Yes, sounds like a bug. I can't think of a scenario where a read-only account would need to add contributors

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants