Descriptive summary
- Depositors can change the permissions of a work and its files in an admin set that should restrict these permissions.
- Admin sets meant to only allow "Private" permissions are being overridden by non-admin users
Steps to reproduce the behavior in User Interface (UI)
Reproducing Issue: Public Work in Private Admin Set
- As a non admin user, create a new work in Nurax.
- Select an admin set with exclusive private visibility in the Relations tab.
- In the Sharing Settings tab, select "public" for "Add group"
- Fill out the form as usual and add a file. Note that private visibility is checked and is the only available visibility option. Check the deposit agreement and click save.
- Note that the deposited work has public visibility
Extra steps to make the file of the work public:
- Go to the dropdown for the file on the work page and select Edit
- Click the permissions tab and change it from private to public since admin set visibility restrictions aren't being applied to the radio buttons
- Save and note that the file is now public despite being in a private admin set
Acceptance Criteria/Expected Behavior
Descriptive summary
Steps to reproduce the behavior in User Interface (UI)
Reproducing Issue: Public Work in Private Admin Set
Extra steps to make the file of the work public:
Acceptance Criteria/Expected Behavior