Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Informations Disclosure on Main Dashboard ? #421

Closed
EvoXCX opened this issue May 13, 2024 · 2 comments · Fixed by #429
Closed

Informations Disclosure on Main Dashboard ? #421

EvoXCX opened this issue May 13, 2024 · 2 comments · Fixed by #429
Assignees
Labels
bug Something isn't working

Comments

@EvoXCX
Copy link

EvoXCX commented May 13, 2024

Describe the bug
Example Context:
I created a domain with name Domain1 and one user in this group as Domain Administrator.

I created a new domain with name Domain2 and one user in this group as Domain Administrator.

Then I created an Audit on theses 2 domains.

And when I connect with one of theses account I see on Analytics Dashboard certain informations that is not in actual domain.

Expected behavior
Admin from Domain2 can only see his assignment and same for the Admin from Domain1

Screenshots
Admin1 in group Domain1 with all audit and risk assessment
image
image
image

Admin2 in group Domain2 with only 1 audit created
image
image
image

Environment (please complete the following information):

  • Device: Virtual Server
  • OS: Debian 12
  • Browser Edge, Firefox

Maybe it's normal that Dashboard use data from all domains, but it will be fine if we can separe into more little team that do not need to see certain parts.

@ab-smith ab-smith added the question Further information is requested label May 13, 2024
@Mohamed-Hacene Mohamed-Hacene added bug Something isn't working and removed question Further information is requested labels May 13, 2024
@Mohamed-Hacene
Copy link
Collaborator

Mohamed-Hacene commented May 13, 2024

Hi @EvoXCX,

Thanks for this issue, we've noticed this too and are in the process of correcting it. I'll link the pull request to your issue when I push it so that you can follow its progress and test it for your specific application.

@ab-smith
Copy link
Contributor

it's indeed not an information disclosure, but it can be confusing and overwhelming. we'll get it fixed. thank you

@ab-smith ab-smith linked a pull request May 14, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants