No Permission Check When Opening Holdings Editor
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Evergreen |
Confirmed
|
Medium
|
Andrea Neiman |
Bug Description
Evergreen 3.7beta
Staff without CREATE_COPY, CREATE_VOLUME, UPDATE_COPY, and UPDATE_VOLUME can open the holdings editor for all item. Staff then appear to be able to make changes to the holdings details and item attributes but are stopped at Save & Exit by a permission denied message.
Staff with CREATE_COPY, CREATE_VOLUME, UPDATE_COPY, and UPDATE_VOLUME granted at the library depth can also open the holdings editor for all item in the system. If they are editing an item that is owned by another library they will be stopped at Save & Exit by a permission denied message.
Ideally, Evergreen should do a permission check when opening the holdings editor and not allow staff without the applicable permissions to open it.
(Note for testing: The concerto dataset has UPDATE_COPY, and UPDATE_VOLUME granted to the Staff permission group so those permissions are inherited by all other staff permission groups.)
Changed in evergreen: | |
status: | New → Confirmed |
Changed in evergreen: | |
importance: | Undecided → Medium |
Changed in evergreen: | |
assignee: | nobody → Ruth Frasur (rfrasur) |
Evergreen 3.9.1
Evergreen 3.10.1 (Jabok Library)
MOBIUS server
There is no longer an error message when a cataloger from another library attempts to change the circulation and owning libraries. The changes are saved and the item moves to the new "owning" library.
Also, anyone with the UPDATE_COPY can do this. Confirmed Circ1 and LocalAdmin also have the ability to change the owning/circ libraries on an item regardless of working location.