-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Knowledge base show articles without access when impersonate user #14164
Comments
We have the same issue on our side. It would be important that users that are not part of the Target definition could not see the article (not even the topic/header). |
Hi, Can you try to apply #13890 and see if problem persist? |
N o feedback , I close |
@cedric-anne Sorry for the late reply. |
alo! sorry for delay too!,
|
GLPI 10.0.7 will be released tomorrow. You will be able to update directly. |
I can confirm that update to 10.0.7 fix the issue. thanks! |
Code of Conduct
Is there an existing issue for this?
Version
10.0.6
Bug description
When I impersonte user.. the FAQ section with self-service profile shows items he shouldn't have access to
Target is Supervisor profile on Root entity:
the KB is still show on user whitout the Supervisor profile and sub entity:
on click on the item it's show access deny (not bad for security concerns):
The expected result is that this item is not displayed because the user do not have the profile/entity as defined in target
Relevant log output
No response
Page URL
No response
Steps To reproduce
No response
Your GLPI setup information
No response
Anything else?
No response
The text was updated successfully, but these errors were encountered: