Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LCFS - BUG Government user able to use the URL transfer ID to view a transfer in "sent" status #2038

Open
Grulin opened this issue Feb 15, 2025 · 0 comments
Labels
bug Something isn't working Critical Ticket is critical and top priority

Comments

@Grulin
Copy link
Collaborator

Grulin commented Feb 15, 2025

Describe the Bug
We would like to prevent government users from being able to view transfers in a "sent" status by inputting the transfer ID # in the URL

Expected Behaviour
Government IDIR users should not be able to view transfers in a "sent" status

Actual Behaviour
Government IDIR users can view transfers in a "sent" status by inputting the transfer ID # in the URL

Implications
Sent transfers should not be visible to Government users. Only should be visible once they are submitted

Steps To Reproduce
Steps to reproduce the behaviour:
User/Role: IDIR

  1. Go to any transfer
  2. Use the URL to input a number for a transfer that is in a "sent" status
  3. Observe that as an IDIR user, you can view the "sent" transfer
@Grulin Grulin added bug Something isn't working Critical Ticket is critical and top priority labels Feb 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Critical Ticket is critical and top priority
Projects
None yet
Development

No branches or pull requests

1 participant