Repository navigation
Enforce the engagement object permission on the questionnaire answer view - #15666
Conversation
…view Align answer_questionnaire with the other engagement-scoped questionnaire views by always applying the object-level edit check. Adds a regression test.
Maffooch
left a comment
There was a problem hiding this comment.
It is a feature to allow surveys to be answered without a login if configured to be available
|
This pull request has conflicts, please resolve those before we can evaluate the pull request. |
|
Conflicts have been resolved. A maintainer will review the pull request shortly. |
@Maffooch It's been a while, so I forget it we ever talked about this PR elsewhere, but this it should only be minor hardening on questionnaires inside of an engagement which the docs say do not allow anonymous answers even with the setting enabled. It's not particularly important so if I am mistaken then I have no problem throwing this away. |
|
It seems like the docs are wrong from my perspective. The feature is intended to allow anonymous submissions |
Hardening / consistency improvement to the engagement-scoped questionnaire views. Aligns the answer view with its siblings so it always applies the object-level edit permission check, and adds a regression test. No functional change for correctly-permissioned users.