Page MenuHome

SVN management page has too broad permissions
Open, HighPublic

Description

For example, sybren@blender.studio has access to https://cloud.blender.org/p/spring/edit/svnman without being part of the project.

The roles & caps of that user are:

Roles:

demo
org-subscriber
subscriber-pro

Capabilities:

attract-use
attract-view
flamenco-use
flamenco-view
flamenco-view-logs
home-project
subscriber
svn-use

Details

Type
Bug

Event Timeline

Sybren A. Stüvel (sybren) triaged this task as High priority.