Notifications

46 views

Description

Per our licensing rules, only users with the approver_user role can access approvals. This is honored within the platform. However, on the platform any user who has approvals associated with them will see approval records. We should be honoring the role restriction,

Steps to Reproduce

1. Ensure the user Eric Schroeder has no roles in the system except for snc_internal
2. Access the Standard Laptop catalog item from the service catalog and submit.
3. Notice that an approval is requested from Eric.
4. Impersonate Eric.
5. In the platform, the "My Approvals" module is not available for Eric.
6. In  SP, the "My Approvals" widget is still available for Eric on the SP homepage as well as the catalog landing page.
7. He also has access to the approval record and can approve.
 
This provides users to get around our licensing module and allow users to approve without having the appropriate role.

Workaround

This issue is fixed in London. If you are able to upgrade, review the Fixed In or Intended Fix Version fields to determine whether any versions have a planned or permanent fix.

 


Related Problem: PRB1253849

Seen In

Kingston

Fixed In

London

Associated Community Threads

There is no data to report.

Article Information

Last Updated:2018-11-07 13:10:00
Published:2018-10-22