Results 1 to 7 of 7

Thread: Regular user can edit other employees information

  1. #1
    moonvn is offline Junior Member
    Join Date
    Dec 2007
    Posts
    4

    Default Regular user can edit other employees information

    Hi,

    I searched for my issue and found this report. However my case is a little bit different.
    http://www.sugarcrm.com/forums/showt...ight=Employees

    1. Login as normal user.
    2. Click on Employees link.
    3. Click on an employee and edit that record.

    Result: that record is save with amended information.

    My expectation is a user can not edit other employee information.

    I'm using 5.0 beta2

    Which role should I set ? Please help.

    Thanks in advance.
    Last edited by moonvn; 2007-12-20 at 05:07 AM.

  2. #2
    andydreisch's Avatar
    andydreisch is offline Sugar Team Member
    Join Date
    Apr 2005
    Location
    San Jose
    Posts
    2,080

    Default Re: Regular user can edit other employees information

    Hi moonvn, this was addressed some time ago and our GA release does not exhibit this problem. You can verify this in our demo site if you'd like.

    Since Beta2 there have been countless bug fixes that you're not taking advantage of. This is why Sugar does not support production use of pre-GA versions (which are meant exclusively for testing purposes).

    Andy
    Andy Dreisch
    Vice President, Online Team


    Check out our Podcasts!
    Sugar University for training
    Sugar Wiki for developer and user help
    SugarForge for modules, themes, lang packs
    SugarExchange for production-ready extensions
    Enter/view bugs via the Sugar bug tracker

  3. #3
    moonvn is offline Junior Member
    Join Date
    Dec 2007
    Posts
    4

    Default Re: Regular user can edit other employees information

    Quote Originally Posted by andydreisch
    Hi moonvn, this was addressed some time ago and our GA release does not exhibit this problem. You can verify this in our demo site if you'd like.

    Since Beta2 there have been countless bug fixes that you're not taking advantage of. This is why Sugar does not support production use of pre-GA versions (which are meant exclusively for testing purposes).

    Andy
    Hi Andy,

    Thank you very much for your prompt in reply.

    I will setup the released version then

    Best regards,

    Moon

  4. #4
    agcopley is offline Sugar Community Member
    Join Date
    Nov 2007
    Location
    Santiago, Chile
    Posts
    204

    Default Re: Regular user can edit other employees information

    Funny...I am using 5.0.0bCE and this problem is still there! I have a feeling this bugfix was unfixed...QA issues here again.

    Thanks
    Andrew

  5. #5
    JVWay is offline Sugar Community Member
    Join Date
    Sep 2007
    Location
    Corvallis, Oregon
    Posts
    452

    Default Re: Regular user can edit other employees information

    Maybe that's a CE thing. I'm running 5.0.0b enterprise and cannot edit employees with a regular user. I have assigned a Role that allows virtually everything but I am not an admin.

    So you might double check that. It would be interesting to know if it's a CE thing or not.
    Jerry Way
    Business Process Administrator

    Sugar 6.1.4 Professional
    (Testing 6.1.2)
    LAMP on Centos 5
    PHP 5
    MySQL 5
    Apache 2.2

  6. #6
    agcopley is offline Sugar Community Member
    Join Date
    Nov 2007
    Location
    Santiago, Chile
    Posts
    204

    Default Re: Regular user can edit other employees information

    Quote Originally Posted by JVWay
    Maybe that's a CE thing. I'm running 5.0.0b enterprise and cannot edit employees with a regular user. I have assigned a Role that allows virtually everything but I am not an admin.

    So you might double check that. It would be interesting to know if it's a CE thing or not.
    Naaa..it turns out that I can edit only my own details...however this is still wrong! Should be an admin activity.

    Thanks
    Andrew

  7. #7
    kuske's Avatar
    kuske is offline Sugar Community Member
    Join Date
    Oct 2007
    Location
    Germany
    Posts
    2,597

    Default Re: Regular user can edit other employees information

    I tested this in 5.0.0b and normal users do not have the right to edit other users here in my clean installation.
    Even if I hack the calling link from DetailView ti EditView the system gives the correct answer
    "Unauthorized access to administration."

    The fact that a user can edit his own details could be a feature, isn't it?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. report to in USER INFORMATION
    By lucadanzi in forum Help
    Replies: 3
    Last Post: 2006-12-15, 05:45 AM
  2. Replies: 2
    Last Post: 2005-12-13, 02:05 PM
  3. Cannot Login
    By Dillon in forum Help
    Replies: 16
    Last Post: 2004-10-13, 02:52 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •