Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No security controls on WSJF Extension settings. #64

Open
JonFuenningPersonal opened this issue Aug 13, 2024 · 1 comment
Open

No security controls on WSJF Extension settings. #64

JonFuenningPersonal opened this issue Aug 13, 2024 · 1 comment
Labels
investigation investigation

Comments

@JonFuenningPersonal
Copy link

We were expecting that the WSJF Extension settings https://dev.azure.com//_settings/MS-Agile-SAFe.WSJF-extension.wsjf-settings-hub would only be modifiable by Project Collection Administrators. We are finding that any user can make changes to the field mappings and Rounding settings. This is not acceptable to us. The ability to make changes must be locked down to members of Project Collection Administrators group.

@AminTi
Copy link
Collaborator

AminTi commented Sep 5, 2024

Thank you for raising this concern. We understand the importance of restricting access to WSJF Extension settings. We appreciate your feedback and will update you once we have made the necessary adjustments. Thank you for your patience.

@AminTi AminTi added the investigation investigation label Sep 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
investigation investigation
Projects
None yet
Development

No branches or pull requests

2 participants