Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0010659Openbravo ERPC. Securitypublic2009-09-10 14:462009-10-13 12:11
villind 
alostale 
urgentmajoralways
closedfixed 
5
2.40MP8 
2.40MP10 
Core
No
0010659: Adding a new organization adds org access to manual roles
Adding a new organization adds org access to manual roles. This poses a security risk as the access control settings are modifid automatically where they should not be modified.
 1. Have an role with ismanula setting active.
 2. Add a new organization
 3. Relogin
 4. See the "Org Access" tab of the manual role
See the attached patch.
No tags attached.
blocks defect 0010548 closed alostale Adding a new organization adds org access to manual roles 
Issue History
2009-09-18 14:08rafarodaTypedefect => backport
2009-09-18 14:08rafarodafix_in_branch => 2.40
2009-10-02 08:50hgbotCheckin
2009-10-02 08:50hgbotNote Added: 0020649
2009-10-02 08:50hgbotStatusscheduled => resolved
2009-10-02 08:50hgbotResolutionopen => fixed
2009-10-02 08:50hgbotFixed in SCM revision => http://code.openbravo.com/erp/stable/2.40/rev/f09cdd91178477ccedef0127213ea2146065b963 [^]
2009-10-13 12:11sureshbabuStatusresolved => closed
2009-10-13 12:11sureshbabuNote Added: 0020981
2009-10-13 12:11sureshbabuFixed in Version => 2.40MP10

Notes
(0020649)
hgbot   
2009-10-02 08:50   
Repository: erp/stable/2.40
Changeset: f09cdd91178477ccedef0127213ea2146065b963
Author: Asier Lostalé <asier.lostale <at> openbravo.com>
Date: Fri Oct 02 08:47:52 2009 +0200
URL: http://code.openbravo.com/erp/stable/2.40/rev/f09cdd91178477ccedef0127213ea2146065b963 [^]

fixed bug 0010659: Adding a new organization adds org access to manual roles

---
M src-db/database/model/triggers/AD_ORG_TRG.xml
---
(0020981)
sureshbabu   
2009-10-13 12:11   
Tested working fine, organization not added to the org access to manual roles