Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non-managers are able to edit group members and systems #34

Open
cjokeefe opened this issue Dec 13, 2017 · 0 comments
Open

Non-managers are able to edit group members and systems #34

cjokeefe opened this issue Dec 13, 2017 · 0 comments

Comments

@cjokeefe
Copy link
Collaborator

cjokeefe commented Dec 13, 2017

Relevant endpoint: DELETE /api/groups/removeUser

While viewing a group as a basic user (not the manager of the group) you are able to add/remove other users from the group and edit systems when this is supposed to be a manager privilege.

@mangoslicer mangoslicer changed the title Non-managers are able to remove group members Non-managers are able to edit group members and systems Dec 14, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant