Description of problem: The interaction of the old implicit job sharing model and the new ability to create your own user groups means it is possible to get additional access to another user's jobs by creating a group and adding them to it. Version-Release number of selected component (if applicable): Beaker 0.13 How reproducible: Always Steps to Reproduce: 1. User A submits an individual job 2. User B creates a new group and adds User A 3. User B has additional access to jobs submitted by User A Actual results: User B has additional permissions on all jobs submitted by User A Expected results: User B has no additional access to any individual jobs submitted by User A, ior group jobs submitted for groups of which User B is not member.
http://gerrit.beaker-project.org/#/c/2130/
verified on beaker-devel (2013-8-12)-->pass steps: 1. User B has no additional access to any individual jobs submitted by User A 2. User B has no access to group jobs submitted for groups of which User B is not member.
Beaker 0.15 has been released.