Bug #11837
closed
[API][Workbench] user can see other users' trash
Added by Radhika Chippada over 7 years ago.
Updated over 7 years ago.
Assigned To:
Radhika Chippada
- Status changed from New to In Progress
Branch 11837-trash-access has two failing tests, one each in controllers/trash_items_controller_test.rb and integration/trash_test.rb
- Assigned To set to Radhika Chippada
- Target version set to 2017-06-21 sprint
- Status changed from In Progress to Resolved
- % Done changed from 0 to 100
Applied in changeset arvados|commit:0e3369b7179c4e483faf681e67279d762feaa33c.
Nico asked: Radhika ... how can I test if the bug is present ?
Nico, I am sorry. I forgot to send you the instructions (as promised) before merging the code into master.
To test: need to login as a non-admin user and visit the https://workbench.4xphq.arvadosapi.com/trash page. Now you will see trashed collections in this user's projects or any other shared collections. Before the fix, the page listed the same collections as when an admin user accesses this page.
Also available in: Atom
PDF