View Issue Details

This bug affects 1 person(s).
 250
IDProjectCategoryView StatusLast Update
13618Feature requestsSecuritypublic2022-03-31 11:36
Reporterhstiekema Assigned To 
PrioritynoneSeverityfeature 
Status newResolutionopen 
Summary13618: Users can delete their own surveys, even without permission
Description

I have created several survey administrators and only gave them permission to create surveys. Based on the create-only permission they get WAY too many privileges. Right now they are able to remove surveys (and because they can, obviously someone does just that) even if i didn't give them permission to delete surveys.

Additional Information

I know the current functionality is intended behaviour but i very much don't agree with that. We're running into users violating the law (mandatory rentention) by removing older versions of surveys they no longer want to use. I need to prevent them from being able to do this.

I appreciate the permission-distinction between own/other surveys, but i need to be able to set more finegrained permissions for own surveys as well. Being able to create a survey should not imply by default that you can remove it as well. Same holds for (de)activating.

I need my users to only be able to define and edit a survey and after activation they should be able to view (not edit/delete!) survey participants and that's it. Absolutely nothing else! (de)Activation, invitations etc is done through RemoteAPI by a different user that's added to the survey as a participant.

TagsNo tags attached.
Bug heat250
Story point estimate
Users affected %

Users monitoring this issue

There are no users monitoring this issue.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2018-04-19 14:43 hstiekema New Issue
2018-05-16 13:06 LouisGac Assigned To => LouisGac
2018-05-16 13:06 LouisGac Status new => assigned
2021-11-25 10:07 galads Zoho Project Synchronization => |Yes|
2021-11-25 10:07 LimeBot Zoho Projects ID => 85781000001460025
2021-11-25 10:07 LimeBot Zoho Projects URL => https://projects.limesurvey.org/portal/limesurvey#taskdetail/85781000001335039/85781000001348001/85781000001460025
2021-11-25 10:07 galads Assigned To LouisGac => galads
2022-03-31 11:35 galads Zoho Project Synchronization Yes =>
2022-03-31 11:35 galads Zoho Projects ID 85781000001460025 =>
2022-03-31 11:36 galads Assigned To galads =>
2022-03-31 11:36 galads Status assigned => new