GetFile Privilege Can Be Bypassed In The View Versions Table For Items
(Doc ID 2830009.1)
Last updated on DECEMBER 22, 2021
Applies to:
Oracle Agile Product Collaboration - Version 9.3.6.0 and laterInformation in this document applies to any platform.
Symptoms
ACTUAL BEHAVIOR
Users can bypass the privilege mask for GetFile privilege by accessing the file through the View Versions table on the attachment tab of Items.
EXPECTED BEHAVIOR
The Get button should be grayed out for users who do not have the GetFile privilege
STEPS
- Log into Java client (http://server:port/JavaClient/start.html)
- Select from the Admin tab User Settings > Roles
- Create a new Role
- Add the following privileges to the Role
Discover Changes
Discover Items
GetFile Items
Modify Preliminary Items
Read Changes
Read Items
ViewFile Items
ViewFile Engineering Change - Save the settings and assign this Role to a test user
- Log into Web Client using the test user (http://server:port/Agile/PLMServlet)
- Opened a Document object D0001234
- Selected Rev 004 from the drop down.
- Get is grayed out and user can not download the file using GET
- Selected from the More > View Versions menu
- User can GET the attachment from the Versions window
Changes
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Changes |
Cause |
Solution |
References |