Bug #6057
open[Post Job – Access] Non-assigned users can update Post-Job status
0%
Description
🔹 Issue Summary:
During job creation, a Team Lead is assigned. However, any Admin or Manager can update the Post-Job status, even if they are not the assigned Team Lead.
🔹 Business Concern:
Job is assigned to a specific Team Lead, so only that user (or defined role) should handle "Under Review" and post-job updates.
🔹 Steps to Reproduce:
1. Create a job and assign it to Team Lead A
2. Login with another user (Admin / Manager / different Team Lead)
3. Open the same job
4. Update Post-Job status
🔹 Expected Result:
Only the assigned Team Lead (or configured role) should be allowed to update post-job status.
🔹 Actual Result:
Any Admin or Manager can update the post-job status.
🔹 Impact:
Unauthorized updates and process inconsistency.
🔹 Clarification Needed:
Please confirm whether role-based restriction is required.
Subtasks
Related issues
No data to display