After upgrading to PL5 we're noticing that users who have not been configured in the request type's User Access tab to have Cancel rights nonetheless have them. Can anyone else confirm this issue? We no longer have a PL 3 or 4 instance to test with.
In any ol' Request type that I open up, for instance 'all users' don't have access to 'cancel', yet I see the cancel-button on a new Request that is unsubmitted. Once submitted, the cancel button is gone. thus, cancellation only possible in unsubmitted status in that scenario.
Mind yout that I'm talking about the undlayed blue button, not the workflow action button on a 'bug'-ootb request type.
So which button are you referring to and under which circumstances do you see it?
Also, does this apply to both pre- and post-upgrade request types?
Had a quick look-see into the knowledge-base but didn't find anything.
Let me know where you see it and I'll try and reproduce. didn't check earlier SPs or hotfix-sets up to know since I want to verify the scenario first but can do afterwards.
Thanks for looking. I tested on two pre-upgrade request types...both custom but built from the PFM - Project and Project Issue request types.
I'm talking about the little 'Cancel Request' button in the lower right of a page. We've always reserved the Cancel and Delete rights for PPM Admin group only. Since upgrade (from PL3), I've had two cases of people who canceled requests inadvertantly but who should not have had the ability to do so. One was an in-flight project, which required some work to recover!
I do have an instance of 9.20 up, maybe I'll have a look in there. Just wanted to see if others saw this before I go off logging a ticket with support.
So is the issue that although the cancel grants are not ticket in the user access tab of the RT, the users are still seeing the cancel-button?
Yes, that's what we're seeing. We've configured the RTs such that only PPM Admin has the Cancel & Delete options ticked in the User Access tab. We're now seeing that project managers see both the cancel and delete options, and not just for their own projects either.
I don't have any P3 or P4 at hand that I can 'just' upgrade like snap.
I can tell you that if you have time until past Easter (Tuesday latest) I can set up an instance plus user access grants (can you attach screenshot of the RT user access tab) on 0004 and then do a deploy of 0005 and see what happens. I won't be managing that before Friday though.
Alternatively, log a ticket with us if it can't wait.
tried to reproduce but have a slight blackout here. The Request Type is configured accordingly but right now, I don't know how to make this Project Request Type visible in the 'Create' -> 'Request' menu for choosing to create it.
Checked the RT as well as the RHT but missing the ticbox where I active the Project Request type as a Request.
Hi, Erik, Fyi, we also recently upgraded to PPMC Version 9.14.0005 a few weeks back. But when I check our instance, we are NOT experiencing that "Cancel" security like you mentioned here. The Cancel button in our case is only available for users/groups who have been provided with Cancel rights in Request Type's User Access tab.
maybe I'M just being a dumb-ass, but I tested this some more and I cannot create a REQUEST from the type PFM - Project by following the menu Create -> Request. This WILL work for assets and proposals but not for projects with the PFM - Project field group active in the RHT.
Thus, I cannot reproduce the problem.
It would need more information from your side on how you set up the RT and RHT and how you actually create this request.