[Koha-bugs] [Bug 13582] New: Able to view menu for Circulation History even when user does not have permission

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Wed Jan 14 22:16:04 CET 2015


http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=13582

            Bug ID: 13582
           Summary: Able to view menu for Circulation History even when
                    user does not have permission
 Change sponsored?: ---
           Product: Koha
           Version: master
          Hardware: All
                OS: All
            Status: NEW
          Severity: enhancement
          Priority: P5 - low
         Component: Patrons
          Assignee: koha-bugs at lists.koha-community.org
          Reporter: tomsStudy at gmail.com
        QA Contact: testopia at bugs.koha-community.org
                CC: gmcharlt at gmail.com, kyle.m.hall at gmail.com

Same problem as Bug 10943. The page requires borrowers to access but the menu
item is still shown to users who do not have the borrowers permission.

>From readingrec.pl we see:
    flagsrequired => {borrowers => 1},

Yet in the include the only thing checked is:
    [% IF ( readingrecordview ) %]

So a user who doesn't have permission to access Circulation history can still
see the menu item.

-- 
You are receiving this mail because:
You are watching all bug changes.
You are the assignee for the bug.


More information about the Koha-bugs mailing list