You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, any user with permission to view all domain requests for a portfolio can access a view-only view of any domain request by going into the browser and hitting the /domain-request/viewonly/{domain id} endpoint manually. This appears to be because the PortfolioDomainRequestsViewOnly view only checks if that view all permission exists, and not whether it exists for the domain requests portfolio.
Acceptance criteria
Portfolio users can only view domain requests that are in their portfolio
Additional context
No response
Links to other issues
No response
The text was updated successfully, but these errors were encountered:
Issue description
Currently, any user with permission to view all domain requests for a portfolio can access a view-only view of any domain request by going into the browser and hitting the /domain-request/viewonly/{domain id} endpoint manually. This appears to be because the PortfolioDomainRequestsViewOnly view only checks if that view all permission exists, and not whether it exists for the domain requests portfolio.
Acceptance criteria
Additional context
No response
Links to other issues
No response
The text was updated successfully, but these errors were encountered: