Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-8578

Permissions not enforced for Query and Trigger Gerrit Patches feature

    XMLWordPrintable

Details

    Description

      Our hudson is configured so that anonymous has no access (view, triggers build, nothing). Yet, without logging in, you can go to Query and Trigger Gerrit Patches, type in a query, and trigger builds. The UI says no jobs were triggered, but after logging back in, the job was indeed triggered. The Query and Trigger Gerrit Patches should at the minimum check that the logged in user has the Build permission for that specific job.

      Attachments

        Activity

          ccutrer Cody Cutrer created issue -
          ccutrer Cody Cutrer made changes -
          Field Original Value New Value
          Issue Type Bug [ 1 ] Improvement [ 4 ]
          rsandell rsandell made changes -
          Resolution Fixed [ 1 ]
          Status Open [ 1 ] Closed [ 6 ]
          rtyler R. Tyler Croy made changes -
          Workflow JNJira [ 138689 ] JNJira + In-Review [ 204850 ]

          People

            rsandell rsandell
            ccutrer Cody Cutrer
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: