Report Card Options Allows Saving to GRP Table Without GRP Permissions
On the Report Card Options page, users can customize headers for Grade Report (GRD) marks. These customizations are saved into the Grade Report Mark Headings (GRP) table for any selected Grading Periods.
Currently, users who have GRD update permissions—but do not have GRP update permissions—are still able to save changes to the GRP table.
This creates a permissions bypass where users can modify GRP data without having the appropriate GRP access. We need the GRP permissions to be enforced.
4
votes
