Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-9842

[Security]-[Authorization Failure] Employee & Company Admin can access the 'Dashboard Configuration' page over the URL.

    Details

    • Type: Bug
    • Status: In Development
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Environment:
      Production, Stage, QA
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Admin, Employee
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - On Hold
    • Issue Importance:
      Q2
    • Browser:
      Google Chrome
    • Sprint:
      WT Sprint 33-Bugs

      Description

      [Security]-[Authorization Failure] Employee & Company Admin can access the 'Dashboard Configuration' page over the URL.

      Replication Steps:
      1. Login as Partner in workterra
      2. Go to Company Dashboard page.
      3. Copy the URL.
      4. Login as Employee or Company Admin in other browser
      5. Paste the URL for Employee or Company Admin to access.

      Actual result:
      Employee & Company Admin can access the Dashboard Configuration Settings page and can update the Employee level settings

      Expected Result:
      If the access is allowed then, "Dashboard Configuration" should be listed in Menu Items for Company Admin and Employee
      It the access not allowed then "Unauthorized Access" page should be displayed.

      Issue tested on Azure and Stage.

      CC : Rakesh RoySamir

        Attachments

          Issue Links

            Activity

            Hide
            aditya.vishwakarma Aditya Vishwakarma (Inactive) added a comment - - edited

            This is due to design.
            This will be restructured in UI Refresh.

            Jaideep Vinchurkar

            Show
            aditya.vishwakarma Aditya Vishwakarma (Inactive) added a comment - - edited This is due to design. This will be restructured in UI Refresh. Jaideep Vinchurkar
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            CC : SatyaVijayendra ShindeRakesh Royshyam sharmaBharti SatputeSamir

            These kind of issue are present on Azure-UI Refresh environment too.
            Please confirm.

            Show
            prasadp Prasad Pise (Inactive) added a comment - CC : Satya Vijayendra Shinde Rakesh Roy shyam sharma Bharti Satpute Samir These kind of issue are present on Azure-UI Refresh environment too. Please confirm.
            Hide
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment -

            Yes there are such issues on UI refresh. But the menu structure is complete different on UI refresh so there should be a task to upgrade / change access policy.

            Show
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment - Yes there are such issues on UI refresh. But the menu structure is complete different on UI refresh so there should be a task to upgrade / change access policy.
            Hide
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment -

            Sorry, I take my words back. Company admin should not have access to global level menus.
            Aditya Vishwakarma, please remove page level access of compay admin for dashboard configuration page.

            Show
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment - Sorry, I take my words back. Company admin should not have access to global level menus. Aditya Vishwakarma , please remove page level access of compay admin for dashboard configuration page.
            Hide
            aditya.vishwakarma Aditya Vishwakarma (Inactive) added a comment -

            Marking it as on hold due to WT-9613

            Show
            aditya.vishwakarma Aditya Vishwakarma (Inactive) added a comment - Marking it as on hold due to WT-9613
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Hi Vijayendra Shinde

            I have verified Over the URL access for Admin User for "Company Module Mapping" tab. It is fixed now. Admin gets the "Unauthorized Access" page when try to access " Company Module Mapping" tab.

            However, following are Global Settings menu which are accessible to Admin user over the URL.

            • Clone Company - Access Allowed & Page displayed.
            • Manage Partner/Broker Users - Server Error Pop-up gets displayed
            • User Credential Settings - Access Allowed & page displayed.

            Expected output is, Unauthorized Access page should get displayed.

            Show
            prasadp Prasad Pise (Inactive) added a comment - Hi Vijayendra Shinde I have verified Over the URL access for Admin User for "Company Module Mapping" tab. It is fixed now. Admin gets the "Unauthorized Access" page when try to access " Company Module Mapping" tab. However, following are Global Settings menu which are accessible to Admin user over the URL. Clone Company - Access Allowed & Page displayed. Manage Partner/Broker Users - Server Error Pop-up gets displayed User Credential Settings - Access Allowed & page displayed. Expected output is, Unauthorized Access page should get displayed.

              People

              Assignee:
              vijayendra Vijayendra Shinde (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Dev Due Date:

                  Time Tracking

                  Estimated:
                  Original Estimate - 0h
                  0h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 49h
                  49h