Users with the worker role can reassign tasks to others even when their permissions are set to view-only in the admin panel.
Steps to Reproduce:
- Assign
worker role to UserA with view-only tasks permission.
- As UserA, navigate to
Tasks → Reassign a task to UserB.
- Observe successful reassignment.
Expected Behavior:
- Reassignment button should be disabled/hidden for
view-only users.
Actual Behavior:
- Silent permission bypass.
Environment:
- Tania Core: v1.6.2 (Community Edition)
- Auth: JWT
Evidence:
// API Response (should fail with 403)
{"status": "success", "message": "Task reassigned"}