Case Resource shows contact names that are not accessible to logged in user
To replicate -
- Add contact A, B and C to case resource group.
- Create a case for User1 and make sure that user1 is able to access only contact A (add appropriate ACL or relationships, etc).
- Log in as User1 and navigate to Manage case screen -> open "Other relationship" panel.
- Notice that "Case Resources" section displays all the 3 contacts A, B and C in the list instead of showing only A to the user.
IMO - this group contacts should only be shown to users having access to view them?