Unauthorised user able to access report editor. #28740
bartosz-galaszewski
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Currently when user is assigned with a role which doesn't allow to edit charts, although not being able to save new chart, he can still click "Edit Chart" and view e.g. table names and fields structure.
It would be highly advisable to disable this as it creates a risk of exposing data such as calculations, metrics, field names and tables to users who supposedly should only be able to view the report itself.
Is anyone aware that this is possible or does it require adding new functionality?
Beta Was this translation helpful? Give feedback.
All reactions