Details
-
Bug
-
Resolution: Unresolved
-
Critical
-
None
-
None
-
Rank:0|ii1frz:
Description
I have a custom user group that has the minimum permissions possible plus these:
- Create/Edit subjects.
- Read MR Sessions.
- Create/Edit MR Sessions.
Yet, for a user added to this custom user group, when there's an xnat:xaSessionData session in this project's prearchive, the user can:
- See the session (they shouldn't, right?)
- Rebuild the session.
- Delete the session (they definitely shouldn't be able to do that).
- Maybe more?