roadmap icon indicating copy to clipboard operation
roadmap copied to clipboard

Plan Collaborators With "Read only" Permissions Are Still Able to Add Contributors to a Plan

Open aaronskiba opened this issue 1 year ago • 4 comments

Please complete the following fields as applicable:

What version of the DMPRoadmap code are you running? (e.g. v2.2.0) v4.2.0

Expected behaviour:

  • I'm not 100% sure. However, I'd assume that collaborators with "read only" access on a plan shouldn't be able to modify it in any way.

Actual behaviour:

  • Plan collaborators with "read only" can successfully add a contributor to a plan. Steps to reproduce:

    1. Add a collaborator and give them "read only" access
  • Screenshot from 2024-07-22 10-05-14

    1. Sign into the app as the added "read only" user and navigate to the corresponding plan
  • Screenshot from 2024-07-22 10-06-06

    1. Try adding a contributor to the plan
  • Screenshot from 2024-07-22 10-06-16

  • Screenshot from 2024-07-22 10-06-49

aaronskiba avatar Jul 22 '24 16:07 aaronskiba

@martaribeiro is this in fact unwanted behaviour?

aaronskiba avatar Jul 23 '24 15:07 aaronskiba

@aaronskiba This looks like a bug.

johnpinto1 avatar Jul 29 '24 11:07 johnpinto1

I think it was @briri who added this feature to Roadmap. Maybe he had a reason to allow a "read only" user to add a contributor to a plan. I asked Diana and Magdalena to see if there was a reason for this. We are not sure either. To me looks like a bug as John said.

martaribeiro avatar Jul 29 '24 11:07 martaribeiro

Yes, sounds like a bug. I can't think of a scenario where a read-only account would need to add contributors

briri avatar Jul 29 '24 15:07 briri