[Vtigercrm-commits] [vtiger development] #5249: Security for Attachments

vtiger development vtiger-tickets at trac.vtiger.com
Mon Mar 31 18:55:07 EDT 2008


#5249: Security for Attachments
------------------------+---------------------------------------------------
 Reporter:  RedneckReg  |       Owner:  developer
     Type:  defect      |      Status:  new      
 Priority:  major       |   Milestone:  5.1.0    
Component:  vtigercrm   |     Version:  5.0.4    
 Keywords:              |  
------------------------+---------------------------------------------------
 It appears that any user can currently delete an attachment assuming they
 have View privileges to a particular Module.  If you are trying to use
 vtiger as any sort of document control mechanism, this access is
 unacceptable.  Please review this thread for more details:

 [http://forums.vtiger.com/viewtopic.php?t=16756]

 At the very least, the deletion of Attachments should be removed for
 Profiles that have View only access.

-- 
Ticket URL: <http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/5249>
vtiger development <http://trac.vtiger.com/>
vtigerCRM




More information about the vtigercrm-commits mailing list