Project and Portfolio Management Practitioners Forum
cancel
Showing results for 
Search instead for 
Did you mean: 

9.14.0005 request type user access bug?

Highlighted
Erik Cole
Honored Contributor

9.14.0005 request type user access bug?

Hi all,

 

After upgrading to PL5 we're noticing that users who have not been configured in the request type's User Access tab to have Cancel rights nonetheless have them. Can anyone else confirm this issue? We no longer have a PL 3 or 4 instance to test with.

14 REPLIES
dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

just checked.

In any ol' Request type that I open up, for instance 'all users' don't have access to 'cancel', yet I see the cancel-button on a new Request that is unsubmitted. Once submitted, the cancel button is gone. thus, cancellation only possible in unsubmitted status in that scenario.

Mind yout that I'm talking about the undlayed blue button, not the workflow action button on a 'bug'-ootb request type.

 

So which button are you referring to and under which circumstances do you see it?

Also, does this apply to both pre- and post-upgrade request types?

 

Had a quick look-see into the knowledge-base but didn't find anything.

 

Let me know where you see it and I'll try and reproduce. didn't check earlier SPs or hotfix-sets up to know since I want to verify the scenario first  but can do afterwards.

 

Have a great day.

Best regards,

dirk

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Dirk,

Thanks for looking. I tested on two pre-upgrade request types...both custom but built from the PFM - Project and Project Issue request types.

I'm talking about the little 'Cancel Request' button in the lower right of a page. We've always reserved the Cancel and Delete rights for PPM Admin group only. Since upgrade (from PL3), I've had two cases of people who canceled requests inadvertantly but who should not have had the ability to do so. One was an in-flight project, which required some work to recover!

I do have an instance of 9.20 up, maybe I'll have a look in there. Just wanted to see if others saw this before I go off logging a ticket with support.

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

using the admin account on 9.14.0005 to view an active project I was able to see the cancel as well as the delete buttons, bottom or top of the  window respectively.

 

With any other user, I didn't have this phenomenon.

Looking at the user access of the tab, the cancel grants is not ticket for any participant, but then I only have the OOTB-particpants set on the RT. 

 

Thus in the RT, no ‘cancel’ grants for anyone.

So is the issue that although the cancel grants are not ticket in the user access tab of the RT, the users are still seeing the cancel-button?

Or do you see that cancel grant, it was just not there before? If so, for which participants – only those added custom or also those that are present ootb? As you can see, I cannot reproduce it.

Guess it doesn’t make much sense to add other participants now to test this – but let me know nevertheless if you see this behavior also for newly added participants.

 

 

Best regards,

Dirk

 

 

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

So is the issue that although the cancel grants are not ticket in the user access tab of the RT, the users are still seeing the cancel-button?

 

Yes, that's what we're seeing. We've configured the RTs such that only PPM Admin has the Cancel & Delete options ticked in the User Access tab. We're now seeing that project managers see both the cancel and delete options, and not just for their own projects either.

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Erik

 

I don't have any P3 or P4 at hand that I can 'just' upgrade like snap.

I can tell you that if you have time until past Easter (Tuesday latest) I can set up an instance plus user access grants (can you attach screenshot of the RT user access tab) on 0004 and then do a deploy of 0005 and see what happens.  I won't be managing that before Friday though.

 

Alternatively, log a ticket with us if it can't wait.

 

Best regards,

Dirk

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

No problem, I mainly wanted to do a quick poll before spending more time gathering enough screenshots, etc to put in a support ticket.

 

Here's the RT config:

 

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

tried to reproduce but have a slight blackout here. The Request Type is configured accordingly but right now, I don't know how to make this Project Request Type visible in the 'Create' -> 'Request' menu for choosing to create it.

Checked the RT as well as the RHT but missing the ticbox where I active the Project Request type as a Request.

 

Best regards,

Dirk

Raj Ghimire
Occasional Visitor

Re: 9.14.0005 request type user access bug?

Hi, Erik,
Fyi, we also recently upgraded to PPMC Version 9.14.0005 a few weeks back. But when I check our instance, we are NOT experiencing that "Cancel" security like you mentioned here. The Cancel button  in our case is only available for users/groups who have been provided with Cancel rights in Request Type's User Access tab.

 

Thanks.

-Raj

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

Dirk - RT is enabled?

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

gave me a fright there, but yes, it is enabled. Thing is, a request type of the type 'Project' isn't shown in the create-menu. I can search on these Request Types, but not create them.

So do you use the Project Request Type to create Projects or are you really talking about Requests?

 

Best regards,

Dirk

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

Can you do a Create > Request and find your project RT in there? I think you have to have the PFM content pack (whatever they're calling it now) for the Project menu items.

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

that's the issue that I'm having.

Create -> Request doesn't show the RT that I edited.

The Search DOES show the RT

The 'Eric Project Type' RT that I have configured for this is an edited RT and direct copy of the 'PFM - Project' RT.

 

Puzzled...

 

Best regards,

Dirk

Erik Cole
Honored Contributor

Re: 9.14.0005 request type user access bug?

So maybe there are more issues with RT security than mine...?

dirkf
Honored Contributor

Re: 9.14.0005 request type user access bug?

Hi Eric,

 

maybe I'M just being a dumb-ass, but I tested this some more and I cannot create a REQUEST from the type PFM - Project by following the menu Create -> Request. This WILL work for assets and proposals but not for projects with the PFM - Project field group active in the RHT.

Thus, I cannot reproduce the problem.

It would need more information from your side on how you set up the RT and RHT and how you actually create this request.

 

Best regards,

Dirk

//Add this to "OnDomLoad" event