A user having only read access via OBS to a Project instance, is still able to edit some fields.
The steps to reproduce are as follows:
- Assign the user to OBS 1 and Group 1.
- Grant Project-Read access to OBS 1.
- Add an instance of the Project to the OBS 1.
- Verify that the user is not able to edit any field on the Project.
- Implement Field Level Security on one of the fields and grant edit rights to the Group 1.
- The user is now able to edit the field on the Project.
Release : 15.9.1
Component : CA PPM APPLICATION
Secure Field Level Access is implemented on some fields.
This is working as expected, as per the current design.
FLS (Field Level Security) takes precedence over other rights.
More information regarding the Field Security on the Modern UX can be found on the Documentation: