Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Announcement center "admins" can see every announcement #175

Open
Shen opened this issue Jan 21, 2020 · 1 comment
Open

Announcement center "admins" can see every announcement #175

Shen opened this issue Jan 21, 2020 · 1 comment

Comments

@Shen
Copy link

Shen commented Jan 21, 2020

Steps to reproduce

  1. add user 'user1' to group 'test'
  2. add group 'test' in settings to announcement center admin-groups
  3. post an announcement with user 'user2' to another group (not a group which user1 belongs to).
  4. user1 is able to see the announcement

Expected behaviour

user1 should only see his own announcements and announcements of his groups.

Actual behaviour

user1 is able to see every announcement. It is a breach of privacy if a user can see announcements that are intended exclusively for another group.

Nextcloud version:
16.0.5.1

Announcement Center version:
3.5.1

@Shen Shen changed the title Announcement center "admins" can see every accouncement Announcement center "admins" can see every announcement Jan 21, 2020
@nickvergessen
Copy link
Member

This won't really change for now, because you could otherwise post an announcement and have no way of deleting it again, in case you didnt set a group which you are part of.
Maybe the admin setting should adjusted a bit, but actually i didnt change the app really in a long time due to the lack of free time

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants