Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
P
purescript-gargantext
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 140
    • Issues 140
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 3
    • Merge Requests 3
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • gargantext
  • purescript-gargantext
  • Issues
  • #452

Closed
Open
Opened Oct 20, 2022 by delanoe@anoe
  • Report abuse
  • New issue
Report abuse New issue

Security Issue with Teams

On dev.sub.gargantext.org, I have made a configuration where the bug happens.

In a shared folder, create 2 teams:

  • user1Only
  • user2Only

When connected as user1, on plane navigation, click on the the folder to go up (which should be .. instead of the name of the folder btw). Then user can access to a team he should not be able to see: https://dl.gargantext.org/user1Only.png

In the vertical tree we do not have such issue since we can not go up from the team. From a team: user should not be able to go up.

Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
1
Labels
critical
Assign labels
  • View project labels
Reference: gargantext/purescript-gargantext#452