Uploaded image for project: 'FreePBX'
  1. FreePBX
  2. FREEPBX-9369

Class of Service not denying access to Contact Manager Groups correctly--multiple issues

    XMLWordPrintable

    Details

    • ToDo:
    • Distro:
      FreePBX Distro

      Description

      Found at OTTS workshop Milwaukee:

      Created two External Contact Groups (Vendors and Customers). Added entries. Excluded from User's Class of Service so User should not see Group Names or Entries. User can see both Groups and Entries and Entry Details in Groups in both UCP and REST Apps.

      If I change it so that User's Class of Service has access to one Group but not the other, then the User is granted access to one Group in REST App and not the other Group. The is a bug that seems to be limited to when the User is Denied access to All Groups, they are mistakenly Allowed access to all Groups in the REST App.

      In the User Control Panel, the User is able to access to All Groups all the time, no matter what combination of allowed/denied groups are set in Class of Service. Security seems to be missing completely.

        Gliffy Diagrams

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  tm1000 Andrew Nagy
                  Reporter:
                  david.sovereen@mercury.net David Sovereen
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  5 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    NextupJiraPlusStatus

                    Error rendering 'slack.nextup.jira:nextup-jira-plus-status'. Please contact your Jira administrators.