Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-9842

[Security]-[Authorization Failure] Employee & Company Admin can access the 'Dashboard Configuration' page over the URL.

    Details

    • Type: Bug
    • Status: In Development
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Environment:
      Production, Stage, QA
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Admin, Employee
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - On Hold
    • Issue Importance:
      Q2
    • Browser:
      Google Chrome
    • Sprint:
      WT Sprint 33-Bugs

      Description

      [Security]-[Authorization Failure] Employee & Company Admin can access the 'Dashboard Configuration' page over the URL.

      Replication Steps:
      1. Login as Partner in workterra
      2. Go to Company Dashboard page.
      3. Copy the URL.
      4. Login as Employee or Company Admin in other browser
      5. Paste the URL for Employee or Company Admin to access.

      Actual result:
      Employee & Company Admin can access the Dashboard Configuration Settings page and can update the Employee level settings

      Expected Result:
      If the access is allowed then, "Dashboard Configuration" should be listed in Menu Items for Company Admin and Employee
      It the access not allowed then "Unauthorized Access" page should be displayed.

      Issue tested on Azure and Stage.

      CC : Rakesh RoySamir

        Attachments

          Issue Links

            Activity

            Transition Time In Source Status Execution Times
            Aditya Vishwakarma (Inactive) made transition -
            Open In Development
            17d 20h 52m 1
            Aditya Vishwakarma (Inactive) made transition -
            In Development Rejected
            1d 21h 31m 1
            Aditya Vishwakarma (Inactive) made transition -
            Rejected Reopen
            4h 14m 1
            Jaideep Vinchurkar (Inactive) made transition -
            Reopen In Development
            41d 19h 48m 1

              People

              Assignee:
              vijayendra Vijayendra Shinde (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Dev Due Date:

                  Time Tracking

                  Estimated:
                  Original Estimate - 0h
                  0h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 49h
                  49h