Any user who can view can change book\chapter\page permissions #688

Closed
opened 2026-02-04 21:52:10 +03:00 by OVERLORD · 2 comments
Owner

Originally created by @FDmitryG on GitHub (May 23, 2018).

For Bug Reports

  • BookStack Version: BookStack v0.21.0
Expected Behavior

User with only View permissions can't modify permissions to book\chapter\page he can view.

Current Behavior

Any user that can view any book \ chapter \ page can change permissions to it. So he can set Create \ Update \ Delete permissions for group that he belong.

Originally created by @FDmitryG on GitHub (May 23, 2018). ### For Bug Reports * BookStack Version: BookStack v0.21.0 ##### Expected Behavior User with only View permissions can't modify permissions to book\chapter\page he can view. ##### Current Behavior Any user that can view any book \ chapter \ page can change permissions to it. So he can set Create \ Update \ Delete permissions for group that he belong.
Author
Owner

@ssddanbrown commented on GitHub (May 23, 2018):

Hi @FDmitryG, Thanks for raising this issue.

Can you please post a screenshot of the Role Permissions set on the role in question?

When configuring a role you have the following permissions available:

image

Does un-ticking these not take effect?

@ssddanbrown commented on GitHub (May 23, 2018): Hi @FDmitryG, Thanks for raising this issue. Can you please post a screenshot of the Role Permissions set on the role in question? When configuring a role you have the following permissions available: ![image](https://user-images.githubusercontent.com/8343178/40439173-15926002-5eb2-11e8-8126-c42713e824dd.png) Does un-ticking these not take effect?
Author
Owner

@FDmitryG commented on GitHub (May 24, 2018):

Hi!
Sorry, it is my fault (((
I mixed up this two options in my test user role.

I corrected mistake and check again and all works right!

@FDmitryG commented on GitHub (May 24, 2018): Hi! Sorry, it is my fault ((( I mixed up this two options in my test user role. I corrected mistake and check again and all works right!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/BookStack#688