Bug description
Users on either the new UI or old UI require superuser permissions in order to see finding groups. Even when they are given all other permissions and assigned to the asset, product, engagement, etc. The findings themselves are available, the ability to view the asset, and engagement are also available. Only issue is when they go to see the finding groups for a particular engagement.
Steps to reproduce
Steps to reproduce the behavior:
- Go to All finding groups on a user account who is not a superuser
- Findings Groups should not populate.
Expected behavior
A user when having the permisssion needed to see a given Asset, organization, engagement, etc goes to all finding groups they should be able to see the finding groups of which they have access to see.
Deployment method (select with an X)
Environment information
- Operating System: Ubuntu 24.04
- Docker Compose or Helm version: Docker Compose version v5.1.4
- DefectDojo version: 3.2.300
Bug description
Users on either the new UI or old UI require superuser permissions in order to see finding groups. Even when they are given all other permissions and assigned to the asset, product, engagement, etc. The findings themselves are available, the ability to view the asset, and engagement are also available. Only issue is when they go to see the finding groups for a particular engagement.
Steps to reproduce
Steps to reproduce the behavior:
Expected behavior
A user when having the permisssion needed to see a given Asset, organization, engagement, etc goes to all finding groups they should be able to see the finding groups of which they have access to see.
Deployment method (select with an
X)Environment information