<?xml version="1.0" encoding="utf-8"?>
<!--RSS generated by Flaimo.com RSS Builder [2026-09-30 03:15:48]-->
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"><channel><docs>https://bugs.limesurvey.org/</docs><link>https://bugs.limesurvey.org/</link><description><![CDATA[LimeSurvey bugs and feature requests - Issues]]></description><title>LimeSurvey bugs and feature requests - Issues</title><image><title>LimeSurvey bugs and feature requests - Issues</title><url>https://bugs.limesurvey.org/images/mantis_logo.png</url><link>https://bugs.limesurvey.org/</link><description><![CDATA[LimeSurvey bugs and feature requests - Issues]]></description></image><language>en</language><category>All Projects</category><ttl>10</ttl><dc:language>en</dc:language><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><item><title>20738: New editor denies access to users whose survey access comes from survey group permissions (classic editor works)</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20738</link><description><![CDATA[A user with no superadmin and no global &quot;surveys&quot; permissions, whose access to a survey comes&lt;br /&gt;
from survey group permissions, can open and edit that survey in the classic editor, but the new&lt;br /&gt;
React editor shows &quot;You don't have permission to access this page.&quot;&lt;br /&gt;
&lt;br /&gt;
This is NOT a webserver configuration issue. On the same installation, superadmins use the new&lt;br /&gt;
editor without any problem, and /rest/v1/user-permissions returns HTTP 200 with a valid payload&lt;br /&gt;
for the affected user. urlFormat is 'path', mod_rewrite is enabled, no reverse proxy involved in&lt;br /&gt;
the failing request.&lt;br /&gt;
&lt;br /&gt;
Cause:&lt;br /&gt;
&lt;br /&gt;
The new editor's guard in editor/src/providers/PermissionsProvider.js derives access solely from&lt;br /&gt;
the payload of /rest/v1/user-permissions. That endpoint&lt;br /&gt;
(application/libraries/Api/Command/V1/UserPermission.php) calls Permission::getPermissions($userId),&lt;br /&gt;
which is findAllByAttributes(['uid' =&gt; $userId]) - raw permission rows only.&lt;br /&gt;
TransformerOutputUserPermissions then keeps only entity === 'global' and entity === 'survey'.&lt;br /&gt;
&lt;br /&gt;
As a result, three access paths that Survey::hasPermission() (application/models/Survey.php, used&lt;br /&gt;
by the classic editor) honours are invisible to the new editor:&lt;br /&gt;
&lt;br /&gt;
1. Survey group inheritance - stored as entity = 'surveysingroup', dropped by the transformer.&lt;br /&gt;
2. Survey ownership - Permission::hasPermission() returns true for the entity owner even with no&lt;br /&gt;
   permission row at all. Reproducible by copying a survey: CopySurvey sets owner_id to the&lt;br /&gt;
   copying user, while copySurveyPermissions() only copies the source survey's rows.&lt;br /&gt;
3. Roles - stored with uid = 0 (UserRoleController::applyPermissionFromXML), so they never match&lt;br /&gt;
   the uid lookup.&lt;br /&gt;
&lt;br /&gt;
The REST backend itself is correct: SurveyDetail and the patch handlers use hasSurveyPermission()&lt;br /&gt;
and authorise these users properly. Only the frontend guard rejects them.&lt;br /&gt;
&lt;br /&gt;
Suggested fix: have UserPermission return effective survey permissions (resolving ownership, group&lt;br /&gt;
inheritance and roles), or have the guard query an endpoint that answers &quot;can this user read/update&lt;br /&gt;
survey X?&quot; using Survey::hasPermission().&lt;br /&gt;
&lt;br /&gt;
Additional information:&lt;br /&gt;
&lt;br /&gt;
- git diff 7.0.7+260729..master is empty for PermissionsProvider.js, UserPermission.php and&lt;br /&gt;
  TransformerOutputUserPermissions.php, so the issue is present in the current release.&lt;br /&gt;
- Workaround, not acceptable in production: granting the global &quot;surveys&quot; -&gt; update permission&lt;br /&gt;
  makes the new editor work, but it grants write/activate/expire access to EVERY survey in the&lt;br /&gt;
  installation through the global short-circuit in Survey::hasPermission(), defeating survey group&lt;br /&gt;
  isolation.&lt;br /&gt;
- The attached .lss is a placeholder to satisfy the upload requirement. The survey content is&lt;br /&gt;
  irrelevant to this bug: reproduction depends on the user and survey group permission&lt;br /&gt;
  configuration, which an .lss export cannot carry. The steps below build that configuration from&lt;br /&gt;
  scratch on a clean install.]]></description><category>Security</category><pubDate>Tue, 29 Sep 2026 19:21:38 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20738</guid><comments>https://bugs.limesurvey.org/view.php?id=20738#bugnotes</comments></item><item><title>20737: Index with question by question mode visually roken + usage of nav</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20737</link><description><![CDATA[With vanilla: the index is visually broken, and don't use nav and navigation]]></description><category>Theme editor</category><pubDate>Tue, 29 Sep 2026 12:48:15 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20737</guid><comments>https://bugs.limesurvey.org/view.php?id=20737#bugnotes</comments></item><item><title>20736: Better difference between No response and not activated</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20736</link><description><![CDATA[In survey listing : difference between &quot;No response&quot; and &quot;No response tables&quot;  is unclear.]]></description><category>Ergonomy</category><pubDate>Tue, 29 Sep 2026 12:13:30 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20736</guid><comments>https://bugs.limesurvey.org/view.php?id=20736#bugnotes</comments></item><item><title>20735: Deactivated survey question setting tooltip content is incorrect</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20735</link><description><![CDATA[The tooltip for question attributes in the new React editor displays &quot;Deactivate survey to edit&quot; even when the survey is deactivated. See screenshot below. This can be replicated also on &lt;a href=&quot;https://demo.limesurvey.org/&quot; rel=&quot;noopener&quot;&gt;https://demo.limesurvey.org/.&lt;/a&gt;]]></description><category>Question editor</category><pubDate>Tue, 29 Sep 2026 15:00:56 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20735</guid><comments>https://bugs.limesurvey.org/view.php?id=20735#bugnotes</comments></item><item><title>20734: When DB have an issue unable to fix it</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20734</link><description><![CDATA[If a survey is set as active== Y but the responses table are deleted or disappears (or any other error ) : no way to login and fix the issue.]]></description><category>Other</category><pubDate>Tue, 29 Sep 2026 12:13:15 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20734</guid><comments>https://bugs.limesurvey.org/view.php?id=20734#bugnotes</comments></item><item><title>20733: Vanilla theme Information and Relationships 1.3.1 rules broken</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20733</link><description><![CDATA[In French : [Structure du document incohérente] Zone d'en tête et corps de page. Les zones d'entête et de contenu principal ne sont pas structurées sémantiquement. Pour corriger : Encapsuler la zone d'en tête dans une balise&lt;br /&gt;
&lt;br /&gt;
WCAG 2.1 1.3.1 – Information and Relationships&lt;br /&gt;
&lt;a href=&quot;https://www.w3.org/WAI/WCAG21/Understanding/info-and-relationships.html&quot; rel=&quot;noopener,nofollow&quot;&gt;https://www.w3.org/WAI/WCAG21/Understanding/info-and-relationships.html&lt;/a&gt;]]></description><category>Accessibility</category><pubDate>Tue, 29 Sep 2026 12:27:24 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20733</guid><comments>https://bugs.limesurvey.org/view.php?id=20733#bugnotes</comments></item><item><title>20730: Quotas are not working on encrypted questions</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20730</link><description><![CDATA[I noticed that if I have a quota on encrypted question it does not trigger as expected.]]></description><category>Encryption</category><pubDate>Mon, 28 Sep 2026 09:46:07 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20730</guid><comments>https://bugs.limesurvey.org/view.php?id=20730#bugnotes</comments></item><item><title>20729: Calling export_responses over JSON-RPC with sDocumentType = "csv" always returns HTTP 500 with a TypeError.</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20729</link><description><![CDATA[Calling export_responses over JSON-RPC with sDocumentType = &quot;csv&quot; always returns HTTP 500 with a TypeError. The same call with &quot;json&quot; or &quot;xls&quot; succeeds on the same survey, same session and same user. CSV export from the admin web UI also works. The problem was already present on 6.x and persisted after upgrading to 7.3.0.&lt;br /&gt;
&lt;br /&gt;
When EXPORT_FORMAT is &quot;xls&quot; or &quot;json&quot; works fine, when &quot;csv&quot; it errors. R code that produces error in step export_b64 &lt;- ls_call:&lt;br /&gt;
&lt;br /&gt;
ls_call &lt;- function(method, params) {&lt;br /&gt;
  body &lt;- jsonlite::toJSON(list(method = method, id = 1, params = params),&lt;br /&gt;
                           auto_unbox = TRUE)&lt;br /&gt;
  resp &lt;- httr::POST(LS_API_URL, httr::content_type_json(), body = body)&lt;br /&gt;
  if (httr::http_error(resp)) {&lt;br /&gt;
    # Server-side failures put the actual reason in the body, usually as an&lt;br /&gt;
    # HTML error page -- strip the markup and show just the readable text&lt;br /&gt;
    txt &lt;- httr::content(resp, as = &quot;text&quot;, encoding = &quot;UTF-8&quot;)&lt;br /&gt;
    txt &lt;- gsub(&quot;(?is)&lt;(head|script|style)\\b.*?&lt;/\\1&gt;&quot;, &quot; &quot;, txt, perl = TRUE)&lt;br /&gt;
    txt &lt;- gsub(&quot;&lt;[^&gt;]+&gt;&quot;, &quot; &quot;, txt)&lt;br /&gt;
    txt &lt;- trimws(gsub(&quot;\\s+&quot;, &quot; &quot;, txt))&lt;br /&gt;
    stop(method, &quot;: HTTP &quot;, httr::status_code(resp), &quot;\n&quot;, substr(txt, 1, 2000))&lt;br /&gt;
  }&lt;br /&gt;
  out &lt;- jsonlite::fromJSON(httr::content(resp, as = &quot;text&quot;, encoding = &quot;UTF-8&quot;))&lt;br /&gt;
  if (!is.null(out$error)) stop(method, &quot;: &quot;, out$error)&lt;br /&gt;
  if (is.list(out$result) &amp;&amp; !is.null(out$result$status)) {&lt;br /&gt;
    stop(method, &quot;: &quot;, out$result$status)&lt;br /&gt;
  }&lt;br /&gt;
  out$result&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
session_key &lt;- ls_call(&quot;get_session_key&quot;, list(LS_USER, LS_PASSWORD))&lt;br /&gt;
&lt;br /&gt;
export_b64 &lt;- ls_call(&quot;export_responses&quot;, list(&lt;br /&gt;
  session_key, survey$survey_id, EXPORT_FORMAT, survey$lang,&lt;br /&gt;
  COMPLETION, HEADING_TYPE, RESPONSE_TYPE&lt;br /&gt;
))&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So exporting in xls is the workaround, but given that csv is the standard for data exchange, it would be good to get the &quot;csv&quot; format working.]]></description><category>Import/Export</category><pubDate>Sun, 27 Sep 2026 00:36:38 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20729</guid><comments>https://bugs.limesurvey.org/view.php?id=20729#bugnotes</comments></item><item><title>20728: Answers show encrypted in response view when going to the next page</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20728</link><description><![CDATA[If you have survey with questions where you set encrypted ON, the response view shows the answers encrypted after going to next page.]]></description><category>Response browsing</category><pubDate>Mon, 28 Sep 2026 17:25:51 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20728</guid><comments>https://bugs.limesurvey.org/view.php?id=20728#bugnotes</comments></item><item><title>20726: Question attributes diverge between React editor and classic editor</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20726</link><description><![CDATA[This is a problem as fixes don't reach both editors. In some instances it is even worse as different question attributes are attributed to different question themes. For example this blocks a fix for &lt;a href=&quot;https://bugs.limesurvey.org/view.php?id=18721&quot;&gt;18721&lt;/a&gt;]]></description><category>Question theme</category><pubDate>Thu, 24 Sep 2026 21:36:11 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20726</guid><comments>https://bugs.limesurvey.org/view.php?id=20726#bugnotes</comments></item><item><title>20725: New Question-Editor - missing button/possibility to manual "Data Entry"</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20725</link><description><![CDATA[In the new (!) question editor i can't see a button or possibilty to enter the page &quot;data entry&quot; in a running survey in the category &quot;results&quot;.&lt;br /&gt;
Even not in the &quot;...&quot;-menus.]]></description><category>Other</category><pubDate>Thu, 24 Sep 2026 17:57:30 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20725</guid><comments>https://bugs.limesurvey.org/view.php?id=20725#bugnotes</comments></item><item><title>20724: Page to define or import label sets is not reachable</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20724</link><description><![CDATA[Page to define or import label sets is not reachable.]]></description><category>Label sets</category><pubDate>Fri, 25 Sep 2026 08:30:13 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20724</guid><comments>https://bugs.limesurvey.org/view.php?id=20724#bugnotes</comments></item><item><title>20723: When delete a survey : old responses and token table arenot deleted</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20723</link><description><![CDATA[When deleting a survey: old responses table are not deleted.]]></description><category>Database design</category><pubDate>Thu, 24 Sep 2026 18:03:22 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20723</guid><comments>https://bugs.limesurvey.org/view.php?id=20723#bugnotes</comments></item><item><title>20722: When check data integrity : if you have a old response table : it broke</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20722</link><description><![CDATA[When there are old response table  data inetgrity result throiw a DB error]]></description><category>Database design</category><pubDate>Thu, 24 Sep 2026 17:59:53 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20722</guid><comments>https://bugs.limesurvey.org/view.php?id=20722#bugnotes</comments></item><item><title>20720: Twitter X button is outdated</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20720</link><description><![CDATA[The icon and colors need to be updated. This also requires an update for the Remix icons pack.]]></description><category>Survey editing</category><pubDate>Tue, 29 Sep 2026 15:43:52 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20720</guid><comments>https://bugs.limesurvey.org/view.php?id=20720#bugnotes</comments></item><item><title>20719: Access mode button text is untranslated on state change</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20719</link><description><![CDATA[See screenshot below.]]></description><category>Survey editing</category><pubDate>Tue, 22 Sep 2026 11:45:10 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20719</guid><comments>https://bugs.limesurvey.org/view.php?id=20719#bugnotes</comments></item><item><title>20718: error trying to update to 7.2</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20718</link><description><![CDATA[Call to undefined function getHtmlLangAttributeValue()&lt;br /&gt;
&lt;br /&gt;
/var/www/limesurvey7/application/core/LSETwigViewRenderer.php(690)&lt;br /&gt;
&lt;br /&gt;
678         // (in the future, should be template dependant done via XML file)&lt;br /&gt;
679         $aData[&quot;aSurveyInfo&quot;] = array_merge($aData[&quot;aSurveyInfo&quot;], $oTemplate-&gt;getClassAndAttributes());&lt;br /&gt;
680 &lt;br /&gt;
681         $languagecode = App()-&gt;getLanguage();&lt;br /&gt;
682         if (!empty($aData['aSurveyInfo']['sid']) &amp;&amp; Survey::model()-&gt;findByPk($aData['aSurveyInfo']['sid'])) {&lt;br /&gt;
683             if (!in_array($languagecode, Survey::model()-&gt;findByPk($aData['aSurveyInfo']['sid'])-&gt;getAllLanguages())) {&lt;br /&gt;
684                 $languagecode = Survey::model()-&gt;findByPk($aData['aSurveyInfo']['sid'])-&gt;language;&lt;br /&gt;
685             }&lt;br /&gt;
686         }&lt;br /&gt;
687 &lt;br /&gt;
688         $aData[&quot;aSurveyInfo&quot;]['languagecode']     = $languagecode;&lt;br /&gt;
689         /* Separate from 'languagecode' since some codes (e.g. 'nl-informal') are not valid values for the HTML lang attribute */&lt;br /&gt;
690         $aData[&quot;aSurveyInfo&quot;]['htmllanguagecode'] = getHtmlLangAttributeValue($languagecode);&lt;br /&gt;
691         $aData[&quot;aSurveyInfo&quot;]['dir']              = (getLanguageRTL($languagecode)) ? &quot;rtl&quot; : &quot;ltr&quot;;&lt;br /&gt;
692 &lt;br /&gt;
693         if (!empty($aData['aSurveyInfo']['sid'])) {&lt;br /&gt;
694             $showxquestions                            = App()-&gt;getConfig('showxquestions');&lt;br /&gt;
695             $aData[&quot;aSurveyInfo&quot;]['bShowxquestions']  = ($showxquestions == 'show' ||&lt;br /&gt;
696                 ($showxquestions == 'choose' &amp;&amp; !isset($aData['aSurveyInfo']['showxquestions'])) ||&lt;br /&gt;
697                 ($showxquestions == 'choose' &amp;&amp; $aData['aSurveyInfo']['showxquestions'] == 'Y'));&lt;br /&gt;
698 &lt;br /&gt;
699 &lt;br /&gt;
700             // NB: Session is flushed at submit, so sid is not defined here.&lt;br /&gt;
701             if (&lt;br /&gt;
702                 isset($_SESSION['responses_' . $aData['aSurveyInfo']['sid']]) &amp;&amp;]]></description><category>Assets</category><pubDate>Wed, 23 Sep 2026 10:39:47 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20718</guid><comments>https://bugs.limesurvey.org/view.php?id=20718#bugnotes</comments></item><item><title>20715: Create 2 other ranking system with the same views ?</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20715</link><description><![CDATA[New ranking system can be interesting to have 500 items ranked, but it doesn't interesting if we rank only 2 or 3 items for analysis.&lt;br /&gt;
Maybe we need 3 ranking question type&lt;br /&gt;
&lt;br /&gt;
1. The new one&lt;br /&gt;
2. The old (6.X) one&lt;br /&gt;
3. One with one column by choice and save the rank (see &lt;a href=&quot;https://demo.sondages.pro/714997&quot; rel=&quot;noopener,nofollow&quot;&gt;https://demo.sondages.pro/714997&lt;/a&gt;)]]></description><category>Other</category><pubDate>Mon, 21 Sep 2026 12:26:50 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20715</guid><comments>https://bugs.limesurvey.org/view.php?id=20715#bugnotes</comments></item><item><title>20714: Ranking questions export is not user-friendly</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20714</link><description><![CDATA[When exporting ranking-type questions, there is a need for a more usable export format.]]></description><category>Other</category><pubDate>Tue, 22 Sep 2026 10:35:54 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20714</guid><comments>https://bugs.limesurvey.org/view.php?id=20714#bugnotes</comments></item><item><title>20713: Export ranking response as full answer export only code</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20713</link><description><![CDATA[When exporting ranking response and set Full answer : have only code]]></description><category>Other</category><pubDate>Tue, 22 Sep 2026 08:26:55 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20713</guid><comments>https://bugs.limesurvey.org/view.php?id=20713#bugnotes</comments></item><item><title>20709: Could not Download All Files via selecting with one click</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20709</link><description><![CDATA[In new UI's Results/Responses list when I tried to Download all attached files to that survey via clicking the select all button in header and click Download files below system gives error: &quot;No files to download!&quot;]]></description><category>Statistics</category><pubDate>Mon, 21 Sep 2026 21:59:28 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20709</guid><comments>https://bugs.limesurvey.org/view.php?id=20709#bugnotes</comments></item><item><title>20708: Concurrent response creation for the same participant</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20708</link><description><![CDATA[With long survey and some slow servers, there are multiple creations for one particpant.&lt;br /&gt;
It can happen too on limesurvey hosting]]></description><category>Survey participants (Tokens)</category><pubDate>Sat, 19 Sep 2026 18:18:00 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20708</guid><comments>https://bugs.limesurvey.org/view.php?id=20708#bugnotes</comments></item><item><title>20704: Different behaviour about duplicate by firstname/lastname email when import participant</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20704</link><description><![CDATA[When duplicate is found with import CSV : use owner_id&lt;br /&gt;
When duplicate is found with import from token table : do not use owner_id]]></description><category>Central participant database</category><pubDate>Fri, 18 Sep 2026 08:41:35 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20704</guid><comments>https://bugs.limesurvey.org/view.php?id=20704#bugnotes</comments></item><item><title>20703: Unable to upxdate firstnale lastname when import CSV in CPDB</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20703</link><description><![CDATA[As superadmin : when import existing participant (by ID) : lastname and firstname are not updated]]></description><category>Central participant database</category><pubDate>Sat, 19 Sep 2026 21:36:58 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20703</guid><comments>https://bugs.limesurvey.org/view.php?id=20703#bugnotes</comments></item><item><title>20702: Unclear error when try to import participant without permission</title><author></author><link>https://bugs.limesurvey.org/view.php?id=20702</link><description><![CDATA[When trying to import a user without permission: the errors are unclear]]></description><category>Central participant database</category><pubDate>Mon, 21 Sep 2026 22:01:31 +0200</pubDate><guid>https://bugs.limesurvey.org/view.php?id=20702</guid><comments>https://bugs.limesurvey.org/view.php?id=20702#bugnotes</comments></item></channel></rss>
