Passbolt version 2.5.0, running in docker.
I see that private tags broken, because I can share resource with personal tag to user.
As you can see on the screenshot 1 - password location is root and tag is personal (do not starts from #, so I shouldn’t be able to grant access to this resource). But I shared it and user can see this resource.
The same situation with shared folder. Steps to reprosuce:
- Create some folder.
- May be create a child folder, it does not matter.
- Share this folder to some users.
- Create passwords in this folder. So, now all users from step 3 can see all passwords in this folder.
- Create password with personal tag in this folder.
- Users from step 3 CAN see this password, but they must NOT see it.
On screen 2 you can see access rights inherited from parent folder and shared resource with personal tag.