Page MenuHomePhabricator

User without "can edit" permission, can change task via comment action
Closed, InvalidPublic

Description

Our default Maniphest Task can edit policy is: Who is not assigned, can not edit the Task.

Today we have found an issue :-/ An User can edit the task via comment actions if has NO can edit permission.

  1. Task can edit Policy

Bildschirmfoto_2016-06-17_um_15_10_51.png (814×2 px, 118 KB)

  1. Task Actions

Bildschirmfoto_2016-06-17_um_15_07_14.png (1×2 px, 336 KB)

  1. Moving Task on Workboards seems to respect the can edit policy of the task

Bildschirmfoto_2016-06-17_um_15_14_26.png (718×1 px, 93 KB)

phabricator d1999557dca222ce3aa2bfabd3442c2db93b39d2 (Mon, Jun 6) 
arcanist ca33240942597932075f8e715628b36eebbe68ce (Mon, Jun 6) 
phutil 557309b9242a18518aeaccd099674e889e45a62e (Mon, Jun 6)

Event Timeline

epriestley added a subscriber: epriestley.

This is expected. You do not need edit permission to comment on a task or take other actions available in the action dropdown.

You can customize edit forms to limit these actions, as we do on this install. See:

https://secure.phabricator.com/book/phabricator/article/forms/