Unexpected Admin Access for Limited-Access User #10046
-
On an InvenTree demo site, I created a user and assigned them to a user group with access only to sales. However, after logging in, I found that the user could still access the Admin Center and System Settings, where they were able to perform actions in other modules. Is this expected behavior? Another issue is that the user can still see the Purchase Order widget on the dashboard, even though they don't have permission to access that module. |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 9 replies
-
Does the account have "staff" access? Please provide some screenshots or evidence here for us to work with. |
Beta Was this translation helpful? Give feedback.
-
Yes, the account has "staff" access. After removing the "staff" access, the Admin Center and System Settings were no longer visible. However, the user can still add widgets from other modules to their dashboard. |
Beta Was this translation helpful? Give feedback.
-
It appears that a user can "add" dashboard widgets without the related permissions, but the widgets don't display any data in such a case: ![]() |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
PR incoming here - #10047