mirror of
https://github.com/SuiteCRM/SuiteCRM.git
synced 2026-03-02 19:16:58 -05:00
Incorrect security group inheritance on record modification #5332
Labels
No labels
Area: API
Area: Campaigns
Area: Cases
Area: Clean Up
Area: Clean Up: Performance
Area: Dashlets
Area: Databases
Area: Developer Tools
Area: Elasticsearch
Area: Elasticsearch
Area: Emails
Area: Emails:Campaigns
Area: Emails:Cases
Area: Emails:Compose
Area: Emails:Config
Area: Emails:Templates
Area: Environment
Area: Installation
Area: Language
Area: Mobile
Area: Module
Area: PDFs
Area: PHP8
Area: Reports
Area: Studio
Area: Styling
Area: Upgrading
Area: Workflow
Area:Activity Stream
Area:Calls
Area:Import
Area:Projects
Area:Search
Area:Surveys
Area:Themes
Area:Users
Branch:Hotfix
Good First Issue
Hacktoberfest
Help Wanted
PR:Community Contribution
PR:Type:Enhancement
Priority:Critical
Priority:Important
Priority:Moderate
Severity: Major
Severity: Minor
Severity: Moderate
Status: Requires Code Review
Status: Requires Updates
Status: Stale
Status: Team Investigating
Status:Assessed
Status:Fix Proposed
Status:Needs Assessed
Status:Requires Automated Tests
Type: Bug
Type:Deprecated
Type:Discussion
Type:Duplicate
Type:Invalid
Type:Question
Type:Suggestion
Type:Suggestion
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/SuiteCRM-SuiteCRM#5332
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @SinergiaCRM on GitHub (Jun 24, 2025).
Issue
When "Inherit from Assigned To User" is enabled in Security Suite settings, modifying any record causes the security groups of the assigned user to be re-inherited. This behavior is incorrect, as inheritance should only apply at the time of record creation. This issue is specific to "Inherit from Assigned To User" and does not occur with "Inherit from Created By User" or "Inherit from Parent Record".
Possible Fix
The inheritance logic for "Inherit from Assigned To User" should be modified to apply only during record creation and not upon subsequent modifications.
Steps to Reproduce the Issue
Context
This issue leads to unintended security group assignments on existing records, which can cause data access inconsistencies and potential security access problems.
Version
7.14.6
What browser are you currently using?
Chrome
Browser Version
Versión 131.0.6778.139 (Build oficial) (64 bits)
Environment Information
MySQL, PHP Version 7.4
Operating System and Version
Kubuntu 22.04.4 LTS