Skip to content

A user with admin roles in 1 org is able to access some UI in an 2nd org that they are only a member #392

Closed
coder/coder
#16721
@jaaydenh

Description

@jaaydenh

User is a Org admin in org A
User is just a member in org B

Expected
The user should not see org B in the org selector dropdown or have access to any of the settings pages for org B

Actual

  1. User can access the Members page even though the members page is not in the sidebar
  2. User can access the custom roles page from the sidebar
  3. User can access the groups page through the url directly
  4. The org is incorrectly displayed in the org selector dropdown
Image

Related to this:
A user that is only a member in any org can still access orgs by going directly to the url /organizations/coder

Expected
Org members should not be able to access any organization settings

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions