Web Client: too much patron information is revealed via View Holds
Bug #1705133 reported by
Tina Ji
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Evergreen |
Fix Released
|
Undecided
|
Unassigned | ||
2.12 |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
This is a privacy issue.
Nearly all fields in patron records are available on the column picker on View Holds. The value in these fields are displayed, regardless the patron is outside the org unit's opting-in boundary.
On XUL client, only patron alias, barcode, first/last name and id are on the column picker.
Ideally, information of patrons outside the org unit's opting-in boundary is not be displayed. Or minimum information is displayed like on the XUL client.
Same issue on Show Record Holds via Item Status screen.
Tina Ji
BC Libraries Coop
tags: | added: webstaffclient |
Changed in evergreen: | |
status: | New → Confirmed |
tags: | added: webstaffcolumns |
Changed in evergreen: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
Tina,
Is this bug in reference to the record's View Holds screen or to one of the other holds interfaces?
Thanks!
-Kathy