Actions
Bug #5330
openView Relationships - "Group-Only Member Without Client Assignment Can Access Client Information"
Start date:
08/07/2025
Due date:
% Done:
0%
Estimated time:
Description
TM 1 belongs to Group A
No clients assigned to TM 1
1. Login the Lauditor with TM 1 account
2. Click on Relationships module
3. Click on View Relationships -Individual / Entity / Corporate
- The member is currently able to access client information.
Expectation:
A member who belongs only to a group and is not directly assigned to any clients should not have access to any client details. The client names should be visible in a blurred or masked manner, indicating restricted access.
Note: This issue is applicable in Messages module. No clients should be listed. [Team Chat is only allowed for the member who belongs to group not assigned to any client]
Files
Actions