26B - Unauthorized Access Issue with Journey Task Restricted by Area of Responsibility
Dear Team,
We have identified an issue where users assigned to a specific Area of Responsibility (AOR1) are able to self-assign the journey and access/complete a restricted task. Based on the documented behavior for Journeys and Area of Responsibility, this task should only be accessible to users with AOR1 when they are managing another user’s journey, and not when interacting with their own self-assigned journey.
Context:
A self-assigned journey contains a task intended to be completed only by users assigned to a specific Area of Responsibility (AOR), based on the configured journey access controls.
Navigation:
Me >> Journey >> Explore >> Personal VISA Letter >> Start Journey
Tagged:
0