Ticket

+commit
 
+issues

When...

  • clicking Edit on a formatted card with inclusions, or
  • clicking the Edit...inclusions subtab of any unformatted card with inclusions

...as long as the user has permission to edit any of those cards, show the multi-edit interface, and simply don't offer to edit the cards the user doesn't have permission to edit.

 

If the user doesn't have permission to edit any of the inclusions, give a graceful error message (right now all of these cases return an Application error).

 

 

+example

http://sandwagn.wagn.org/wagn/inclusion_permissions_bug_test

 

(You may have to remove your Administrative User role to see the bug.)

 

wow, this must be an old bug.  sandwagn??  Does this still happen?


hmm, it now appears to over-allow (not underallow). yeah, we need to fix this.

  --Ethan McCutchen.....Thu Jan 06 10:29:40 -0800 2011


Created test cases at http://test.dwagn.org/wagn/partial_permission_in_multi_edit and when testing with a non-Admin account, when I edit either one the field I don't have permission to edit just doesn't show up. What got over-allowed for you?

  --John Abbe.....Thu Jan 06 21:03:12 -0800 2011


it's on the sandwagn example and appears to be narrower than I had feared. It looks to me like if you have permission to edit something that you don't have permission to view (which is admittedly an odd configuration), then you can't edit that card singly, but you can edit it (and therefore see the contents) within a multi-edit context.

 

That's obviously not great, but it's not as bad as I feared. Let's ticket disallow editable but unviewable cards in multi-edit.

 

So is this ticket ready to close?

  --Ethan McCutchen.....Fri Jan 07 10:53:35 -0800 2011