Project

General

Profile

Actions

Bug #2782

open

[Mentors] User can edit any mentor by clicking the 'EDIT' button, although this should be restricted to editing only their own mentors information.

Added by Kristina D about 1 year ago. Updated about 1 year ago.

Status:
New
Priority:
High
Assignee:
Start date:
12/16/2024
Due date:
% Done:

0%

Estimated time:
Severity:
Critical

Description

Environment:
"https://qainterrapt.brainster.xyz/login"

Browser:
PC/Microsoft Windows 11 V. 23H2 (OS Build 22631.4460)/ Version 131.0.6778.86 (official Build) (64-bit)
PC/Microsoft Windows 11 V. 23H2 (OS Build 22631.4460)/ Version 131.0.2903.70 (official Build) (64-bit)
Apple iPhone 14 pro/ iOS Version 18.1.1 (22B91)/ Safari 18.1 on iOS 18.1 (24-bit)

Pre-conditions:
The User is logged in as a regular user on the "Mentors" page, with records of mentors that can be edited.

Steps to reproduce:
1. Login as a regular user.
2. Click on the "Mentors" menu.
3.Find a record from the precondition.
4. Click on the green 'EDIT' button.
5. Observe the Action.

Expected Result:
The 'EDIT' button should be disabled or hidden for regular users, and only accessible for editing their own mentor information.

Actual Result:
Regular users are able to click the 'EDIT' button and edit mentor information for other users, although this action should be restricted to editing only their own mentor information.

Actions

Also available in: Atom PDF