Bug 396

Summary: User Can Edit Assigned Role Restrictions Despite Restricted Role Access
Product: Smartwas Reporter: Mogan (Mogan)
Component: Exploratory Testing BugsAssignee: Hemanth (Hemanth)
Status: OPEN ---    
Severity: Medium CC: SureshAnand
Priority: ---    
Version: unspecified   
Hardware: PC   
OS: Windows   
Associated Test Case ID: Triaged By: ---
Root Cause Analysis (RCA):
Resolution Summary / Fix Details:
Impact Area:

Description Mogan (Mogan) 2026-08-13 13:41:16 UTC
In the Peoples module, an Admin can create and configure roles with restricted access to specific modules and sub-modules. When a user assigned to the restricted role logs into the application, the user is able to access the role details, and the Edit option is available. The user can modify the role restrictions that were configured by the admin, even though the user should not have permission to manage or modify role access.

Additionally, when the user modifies the role restriction from their own portal, the updated access is not reflected immediately. The updated permission is applied only after the user logs out and logs in again.