-
Notifications
You must be signed in to change notification settings - Fork 7.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
projects page on the portal is public anyone can see it #39155
Comments
Anyone please |
@yahyaoudra You can set the role or disable it in the Portal Settings. |
@s-aga-r I have as shown in your screenshot the Role "Customer" set and in a new private window without login the projects are showing. |
@s-aga-r I disabled it and still the same problem |
Same problem here. Under an incognito and unlogged user, I can access the list of projects when they should be private and only accessible when signed in with the correct permissions. erp.example.com/project When I click on erp.example.com/newsletters they are inaccessible and I need to log in, which is correct as I set the newsletters to private. Could you point me to where in the code base I can look to see if I can fix the privacy issue? Thank you. Installed Apps |
The issue is with frappe/erpnext not with frappe/frappe. I explained the fix in erpnext/#39009 |
@0xD0M1M0 There are two issues first one is for permission and second if a Portal Menu is disabled it also not be accessible with a URL. |
transferring this back to ERPNext, ignore the disabled one for now. |
Information about bug
when you visit erpnext path installation erpnext.domaine.com/project
any one can see the list of projects you have with images of assignees ...
Module
portal
Version
ERPNext: v15.2.0 (version-15)
Frappe Framework: v15.1.0 (version-15)
Helpdesk: v0.10.0 (main)
Frappe HR: v16.0.0-dev (develop)
Frappe LMS: v1.0.0 (main)
Installation method
manual install
Relevant log output / Stack trace / Full Error Message.
No response
The text was updated successfully, but these errors were encountered: