Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
4.2.3
-
XRAY 2020 Sprint 10, XRAY 2020 Sprint 11, XRAY 2020 Sprint 12, XRAY 2021 Sprint 1
-
Description
- Create Jira account no_permissions.
- Add another employee to the jira account with user privileges
- Create a Xray project and configure this project permission settings for administratoronly
- Create a TEST
- Execute it in the testrun page
- Add attachment
- using the user with no permission call
curl -H "Content-Type: application/json" -X DELETE -u sin:sin http://localhost:8120/rest/raven/1.0/testrun/117874/attachment/221
Attachments
Issue Links
- is cloned by
-
XRAY-6820 IDOR Leads to unauthorized user to delete attachment on Test issue [Manual Steps]
- Closed