Bug 396 - User Can Edit Assigned Role Restrictions Despite Restricted Role Access
Summary: User Can Edit Assigned Role Restrictions Despite Restricted Role Access
Status: OPEN
Alias: None
Product: Smartwas
Classification: Unclassified
Component: Exploratory Testing Bugs (show other bugs)
Version: unspecified
Hardware: PC Windows
: --- Medium
Assignee: Hemanth (Hemanth)
URL:
Depends on:
Blocks:
 
Reported: 2026-08-13 13:41 UTC by Mogan (Mogan)
Modified: 2026-08-14 06:17 UTC (History)
1 user (show)

See Also:
Associated Test Case ID:
Triaged By: ---
Root Cause Analysis (RCA):
Resolution Summary / Fix Details:
Impact Area:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mogan (Mogan) 2026-08-13 13:41:16 UTC
In the Peoples module, an Admin can create and configure roles with restricted access to specific modules and sub-modules. When a user assigned to the restricted role logs into the application, the user is able to access the role details, and the Edit option is available. The user can modify the role restrictions that were configured by the admin, even though the user should not have permission to manage or modify role access.

Additionally, when the user modifies the role restriction from their own portal, the updated access is not reflected immediately. The updated permission is applied only after the user logs out and logs in again.