Skip to content

Unassigned user can use the direct url to task #1

@plyaskin

Description

@plyaskin

Hi Mark!

Thank you very much for your plugin! This is really needed! :)
I have spotted the issue for this - user can use the direct URL to the task (like kanboard.com/?controller=TaskViewController&action=show&task_id=3&project_id=1) and he has full permission for this. If I turn on the "rewrite URL" some user has permission too. Could you fix it?
And I don't see another tasks as an administrator

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions