Uploaded image for project: 'AdMax'
  1. AdMax
  2. ADMAX-3081

Tagging: user can view multiaccount tag sheets uploaded by other users containing unauthorized accounts

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Won't Fix
    • Affects Version/s: Graffiti v1.00
    • Fix Version/s: Graffiti v1.00
    • Component/s: Reporting
    • Labels:
      None
    • Environment:

      Services-Tagging-Phase-I# 152

      AdMax-Tagging-Phase-I# 115

      DB: staging-db5, staging-db6, staging-db7

      UI: Client-st

      Jboss: staging-jboss5

      Description

      1. Login to Admax as bduffy (an admin user)

      2. Navigate to Home -> Reporting ->Apply Tags

      3. Upload a tagsheet with 6 accounts (attached tagsheet)

      => Observe the upload completed successfully and listed in its Apply Tags grid

      4. Login to admax as gurpreet (a user having access to only 3 of the accounts in the tagsheet used at step# 3)

      5. Navigate to Home -> Reporting ->Apply Tags and check the Apply Tags grid

      Actual Result:

      Observed that tag sheets uploaded at step#3 by admin user is being listed in its Apply Tags grid

      Expected Result:

      As "gurpreet" user has authorization to only 3 of the accounts in the tagsheet, this tagsheet uploaded should not be listed in its Apply tags grid

      Note:

      1. When tried to uplaod the file it shows as upload failed "Unauthorized to upload tags for account MountainGear. No tags will be applied from this tag sheet."

      2. "gurpreet" user is unauthorized to these accounts "1-800-Flowers, 1-800-DENTIST, MountainGear"

      3. Also observed that the tag sheets uploaded at step#3 by admin user is being listed in the Apply Tags grid of user "testanalyst" which is authorize to only 1 of the 6 accounts in the tagsheet uploaded

        Attachments

          Activity

            People

            • Assignee:
              squadrim Mike Squadrito (Inactive)
              Reporter:
              saravanan.t Saravanan (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: