Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
3.3.6, 3.4.3, 3.5
-
MOODLE_33_STABLE, MOODLE_34_STABLE, MOODLE_35_STABLE
-
MOODLE_33_STABLE, MOODLE_34_STABLE, MOODLE_35_STABLE
-
MDL-62600-master -
-
GDPR Followup Sprint 1
Description
Steps to reproduce
- Have a site with the privacy officer role set up
- As the site user, fill some SARs
- Log in as admin
Expected output: Either the admin should not see the page "Site administration > Users > Privacy and policies > Data requests" at all, or the admin should see some relevant information. E.g. number of requests, status of requests or even the full list of requests.
Actual behaviour: The page is shown to the admin with the misleading message "There are no data requests"
Only the privacy officer can see the actual requests.
This is even more serious as there can be problems with the requests processing (e.g. we have them stuck in the "pre-processing" state for some reason) and the admin is not even notified about it.
Attachments
Issue Links
- Testing discovered
-
MDL-63184 is_site_dpo() doesn't check for any capability and it seems it should
-
- Closed
-