SCE 6.2.3 (Build 6658)
I have run in to something that seems strange to me... If I create an IMAP account for a user... Lets call him BOB and create an IMAP mapping for inbound email for BOB and I then create another user called MARY and also create an IMAP email account for MARY why is it that BOB can see Mary's email configuration (not password however) if he chooses "All Email Accounts" .. At which point he can delete Mary's Mail Account settings under Personal Mail Account >> Mary even though he is "BOB" and he is not an admin...
Is this by design or is there a security "issue" ??
Sorry if the answer is obvious but I have searched and searched and am unable to come up with why if here IMAP account is listed as "Personal" that Bob can remove it and the same goes for Mary...She can also see Bobs IMAP account info and either Delete it and or Edit it....


LinkBack URL
About LinkBacks



Reply With Quote

Bookmarks