Skip to content

Finding Groups Require superuser permissions #15840

Description

@ChrisAAAllard

Bug description
Users on either the new UI or old UI require superuser permissions in order to see finding groups. Even when they are given all other permissions and assigned to the asset, product, engagement, etc. The findings themselves are available, the ability to view the asset, and engagement are also available. Only issue is when they go to see the finding groups for a particular engagement.

Steps to reproduce
Steps to reproduce the behavior:

  1. Go to All finding groups on a user account who is not a superuser
  2. Findings Groups should not populate.

Expected behavior
A user when having the permisssion needed to see a given Asset, organization, engagement, etc goes to all finding groups they should be able to see the finding groups of which they have access to see.

Deployment method (select with an X)

  • [X ] Docker Compose
  • Kubernetes
  • GoDojo

Environment information

  • Operating System: Ubuntu 24.04
  • Docker Compose or Helm version: Docker Compose version v5.1.4
  • DefectDojo version: 3.2.300

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions