Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0010548Openbravo ERPC. Securitypublic2009-09-10 14:462009-10-08 00:00
villind 
alostale 
urgentmajoralways
closedfixed 
5
2.40MP8 
2.50MP7 
Core
No
0010548: Adding a new organization adds org access to manual roles
Adding a new organization adds org access to manual roles. This poses a security risk as the access control settings are modifid automatically where they should not be modified.
 1. Have an role with ismanula setting active.
 2. Add a new organization
 3. Relogin
 4. See the "Org Access" tab of the manual role
See the attached patch.
No tags attached.
depends on backport 0010659 closed alostale Adding a new organization adds org access to manual roles 
related to defect 0030057 closed aferraz Org Access added automatically to all roles 
causes design defect 0030253 new Triage Platform Base Automatic roles and initial organization setup inconsistency 
diff no-org-for-manual-role.diff (551) 2009-09-10 14:46
https://issues.openbravo.com/file_download.php?file_id=1733&type=bug
Issue History
2009-09-10 14:46villindNew Issue
2009-09-10 14:46villindAssigned To => rafaroda
2009-09-10 14:46villindFile Added: no-org-for-manual-role.diff
2009-09-18 14:08rafarodaNote Added: 0020208
2009-09-18 14:08rafarodaAssigned Torafaroda => alostale
2009-09-18 14:08rafarodaPrioritynormal => urgent
2009-09-18 14:08rafarodaStatusnew => scheduled
2009-09-18 14:08rafarodafix_in_branch => pi
2009-10-02 08:48hgbotCheckin
2009-10-02 08:48hgbotNote Added: 0020648
2009-10-02 08:48hgbotStatusscheduled => resolved
2009-10-02 08:48hgbotResolutionopen => fixed
2009-10-02 08:48hgbotFixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/ed4e3d66e2f427041aa4cfe4501386475d50f8d4 [^]
2009-10-07 12:48sureshbabuStatusresolved => closed
2009-10-07 12:48sureshbabuNote Added: 0020834
2009-10-07 12:48sureshbabuFixed in Version => 2.50MP7
2009-10-08 00:00anonymoussf_bug_id0 => 2874364
2015-06-03 19:06aferrazRelationship addedrelated to 0030057
2015-06-26 09:17vmromanosRelationship addedcauses 0030253

Notes
(0020208)
rafaroda   
2009-09-18 14:08   
Thank you for the patch Ville.
(0020648)
hgbot   
2009-10-02 08:48   
Repository: erp/devel/pi
Changeset: ed4e3d66e2f427041aa4cfe4501386475d50f8d4
Author: Asier Lostalé <asier.lostale <at> openbravo.com>
Date: Fri Oct 02 08:47:52 2009 +0200
URL: http://code.openbravo.com/erp/devel/pi/rev/ed4e3d66e2f427041aa4cfe4501386475d50f8d4 [^]

fixed bug 0010548: Adding a new organization adds org access to manual roles

---
M src-db/database/model/triggers/AD_ORG_TRG.xml
---
(0020834)
sureshbabu   
2009-10-07 12:48   
Tested, working fine (organization access of the newly created organization not added to the manual role by default)