Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-5472

Multi-org: ACL failure / leakage in CiviEvent

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Trivial
    • Resolution: Fixed/Completed
    • Affects Version/s: 3.0.2
    • Fix Version/s: 3.1
    • Component/s: Core CiviCRM
    • Labels:
      None

      Description

      Tester reported:

      "Using L2a Big Event

      Each CVS can see each other's events at participation registration

      Partcipants leak at "register new participant"

      Adding leaked participant gives error - "Event registration for has been added. You do not have the necessary permission to view this contact." Note even the contact name has been removed from the error message, but you could see it before saving.

      In manage events you cannot see the leaked addition and it is not included in the list of participants. However both appear in L1 Event management screens

      L2a's Big Event appears in L2b's event management screen when one of its participants has been included and gives L2b full configuration opportunities

      In fact even with no participants from your area you can see and configure other areas' events it seems."

      This worked correctly in earlier svn rev 23760.

        Attachments

          Activity

            People

            • Assignee:
              rajan Rajan P Mayekar
              Reporter:
              davej Dave Jenkins
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: