Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Any user can update/delete reviews #4

Open
Roman-Peretiatko opened this issue Jul 28, 2023 · 0 comments
Open

Any user can update/delete reviews #4

Roman-Peretiatko opened this issue Jul 28, 2023 · 0 comments
Labels
Backend bug Something isn't working feature sprint 1 Tasks/Features that should to do on 1 sprint

Comments

@Roman-Peretiatko
Copy link

Roman-Peretiatko commented Jul 28, 2023

Description: Any user can update/delete reviews they are not involved in

Reproducible: always.

Preconditions:
The user is logged in.

Steps to reproduce:

  1. Update/delete a review current user not involved in (not author).

Actual result:
A review is updated/deleted.

Expected result:
A forbidden error must appear.

@Roman-Peretiatko Roman-Peretiatko converted this from a draft issue Jul 28, 2023
@Roman-Peretiatko Roman-Peretiatko moved this from Product Backlog to Bugs in Space2Studymvp Sep 1, 2023
@Roman-Peretiatko Roman-Peretiatko changed the title (SP: 1) Add involvment check before updating/deleting reviews Any user can update/delete reviews Sep 1, 2023
@KhrystynaPavlikovska KhrystynaPavlikovska added bug Something isn't working sprint 1 Tasks/Features that should to do on 1 sprint labels Sep 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Backend bug Something isn't working feature sprint 1 Tasks/Features that should to do on 1 sprint
Projects
Status: Bugs
Development

No branches or pull requests

2 participants