Uploaded image for project: 'translate5'
  1. translate5
  2. TRANSLATE-3911

Hotfolder settings passwort and DeepL API key readable when write protected

    • Critical
    • Configs visibility can be restricted based on a user roles.

      A client-PM user, that has no write access to certain configs like DeepL API key or hotfolder settings password, can still read the defined values in the write protected fields.

      This should not be possible.

      Fields like this should only be accessible for sysadmin and admin roles and project managers - be it for reading or writing.

      This refers to all config data for integrated services or access points. MT resources, Hotfolder, Okapi, t5memory, etc.

            aleksandar Aleksandar Mitrev
            marcmittag Marc Mittag [Administrator]
            Thomas Lauria
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: