Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-19648

User without "edit message templates" permission can edit templates when sending

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 4.7.13
    • Fix Version/s: None
    • Component/s: Core CiviCRM
    • Labels:
    • Versioning Impact:
      Patch (backwards-compatible bug fixes)
    • Documentation Required?:
      User and Admin Doc
    • Funding Source:
      Needs Funding
    • Verified?:
      Yes

      Description

      We should expect one of the following situations if you lack "edit message templates":

      • you can't update templates when you use them in an email
      • you can edit "user-driven messages" but not "system workflow messages"

      Instead, users can edit user-driven templates, but only through sending emails.

      To replicate:

      Have a role with neither Administer CiviCRM nor Edit message templates but with the ability to send messages to contacts.
      Log in as a user with that role.
      Go to a contact, and select Send an email
      Pick a message template
      Edit the template
      Check the box to update the template, and send.

      However, Mailings > Message Templates does not exist in the menu, and attempting to go to the URL for updating the template gets an Access denied error.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              andrewhunt Andrew Hunt
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated: