focalboard
focalboard copied to clipboard
Bug: Guests can access boards linked to a channel
Steps to reproduce the behavior
- Invite a guest to a channel
- Link boards to the same channel
- Login as the guest
- Go to the channel and click on the boards linked on the channel
- See error - guest is able to access those boards even though they're not an explicit member
Expected behavior
Guests should not have access any board unless they were added as an explicit member. See this thread for reference.
Screenshots (optional)
https://user-images.githubusercontent.com/93531870/188013397-d4bc393e-b5ca-40e7-9d2c-bae016aa9b68.mov
Edition and Platform
- Edition: Mattermost Boards (plugin)
- Version: v7.3
- Browser and OS: Chrome on Mac
@wuwinson should the Linked Channels RHS in Channels be rendered for a Guest user at all then?
@Pinjasaur Only for the boards where they are an explicit member. Other boards should be hidden.
While testing this locally I realized that this should probably apply to the Search Boards modal, too. Currently a guest can search for a board they are an implicit member of via a channel association. Is that correct @wuwinson?
Good catch! Yep, guests should not be able to search for any boards they're not an explicit member of.
Good catch! Yep, guests should not be able to search for any boards they're not an explicit member of.
cc @sbishel