Hi,

The 'view reports' permission is used in the Ubercart reports module and therefore issuing this permission provides users of that role unauthorized access to Ubercart reports.

Could this permission be altered to something like 'view reports emf' so that it's unique?

The suggested naming convention for permissions is "action_verb modulename".

Comments

davyvdb’s picture

Status: Active » Fixed

Permission is now "view emf reports". (in head). You should manually update your permissions.

Status: Fixed » Closed (fixed)
Issue tags: -access permissions

Automatically closed -- issue fixed for 2 weeks with no activity.