iris-web
iris-web copied to clipboard
[BUG] [Critical] Access Tab For Cases should only be accessible to administrator user. Administrator can be locked out
Describe the bug
The Access Tab when viewing a case for a standard user (non-admin user) can cause anyone, including administrator users to not be able to access the case.
To Reproduce Steps to reproduce the behavior:
- Go to Manager Case > Select a Case
- Click on Access tab
- Other users can be denied and totally locked out to the case.
TestCase002 not accessible to administrator anymore:
And no way to see and get access to the said case. This works with other users as well. Only the user that set "denyall" access can revert the setting to full access.
Expected behavior A clear and concise description of what you expected to happen.
Screenshots
//getting random error "I can't let you do that Dave"
set deny all access to another analyst
//set read only access to analyst 2
//permission denied to getting access
Additional context Please remove Access tab to cases. Access tab can be access via the following ways: 1st Way:
- Go to Case > Select open
- Then Access Tab
2nd Way
- Go to Manage Cases > Select a case
- <Pop up> then Access tab