Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Users with Portfolio View All Domain Requests permissions can view Domain Requests outside their portfolio #3548

Open
1 task
Matt-Spence opened this issue Feb 20, 2025 · 0 comments
Labels
bug Something that isn't working as intended dev issue is for the dev team Feature: 🏢 Org Model

Comments

@Matt-Spence
Copy link
Contributor

Issue description

Currently, any user with permission to view all domain requests for a portfolio can access a view-only view of any domain request by going into the browser and hitting the /domain-request/viewonly/{domain id} endpoint manually. This appears to be because the PortfolioDomainRequestsViewOnly view only checks if that view all permission exists, and not whether it exists for the domain requests portfolio.

Acceptance criteria

  • Portfolio users can only view domain requests that are in their portfolio

Additional context

No response

Links to other issues

No response

@Matt-Spence Matt-Spence added the dev issue is for the dev team label Feb 20, 2025
@katypies katypies added the bug Something that isn't working as intended label Feb 24, 2025
@katypies katypies moved this from 👶 New to 🎯 Ready in .gov Product Board Feb 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something that isn't working as intended dev issue is for the dev team Feature: 🏢 Org Model
Projects
Status: 🎯 Ready
Development

No branches or pull requests

3 participants