[#8466] - Schedules List Permission Control

Category:
Bug report
Priority:
Normal
Status:
New
Project: Severity:
Major
Resolution:
Open
Component: Reproducibility:
Always
Assigned to:
0

Accessing the URL http://host:port/jasperserver/scheduler/main.html exposes all scheduled jobs, allowing any final user to delete or disable the jobs created by any other user. It's possible even to delete or disable jobs related to reports that the user doesn't have access according to his roles.

v6.2.0
Schedules
jonasformolo's picture
Joined: Sep 9 2015 - 2:12pm
Last seen: 1 year 2 weeks ago

2 Comments:

#1

Hi, we know about this issue, will be fixed in next release.
regards, Mikhailo

#2
  • Severity:Minor» Major

We are running version 6.3.0 and still have this problem with a user seeing all scheduled jobs and not just their own. Was this never resolved in the version following 6.2.0 answered in September 2016 ?

Feedback
randomness