Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0013484Openbravo ERP01. General setuppublic2010-05-31 13:082010-07-16 00:00
rafaroda 
harikrishnan 
highmajoralways
closedfixed 
20Ubuntu 7.10
2.50MP17 
2.50MP20 
Core
No
0013484: User created on Initial Organization Setup has Client Admin role
On Initial Organization Setup a user is created: it is supposed to be the Organization administrator. Nevertheless, this user is automatically given a Client Administrator role.

This could be a security hole specially when different organizations are different companies.
1) Perform an Initial Client Setup http://wiki.openbravo.com/wiki/ERP/2.50/Configuration_Manual/Modeling_your_enterprise#Setting_up_a_client [^]
2) Perform an Initial Organization Setup http://wiki.openbravo.com/wiki/ERP/2.50/Configuration_Manual/Modeling_your_enterprise#Setting_up_an_organization [^]
3) Navigate to General Setup || Security || User and select the Organization User created.
4) In user Roles tab see that the user has been assigned the Client Admin role.
No tags attached.
related to defect 0013483 closed psarobe Role System Administrator visible in Entity Roles 
Issue History
2010-05-31 13:08rafarodaNew Issue
2010-05-31 13:08rafarodaAssigned To => psarobe
2010-05-31 13:08rafarodaRelationship addedrelated to 0013483
2010-06-28 11:06psarobeStatusnew => scheduled
2010-06-28 11:06psarobeAssigned Topsarobe => adrianromero
2010-06-28 11:06psarobefix_in_branch => pi
2010-07-05 12:48jonalegriaesarteTarget Version => 2.50MP21
2010-07-05 12:48jonalegriaesartefix_in_branchpi =>
2010-07-05 12:50jonalegriaesarteTarget Version2.50MP21 => 2.50MP20
2010-07-14 15:31harikrishnanAssigned Toadrianromero => harikrishnan
2010-07-14 15:40hgbotCheckin
2010-07-14 15:40hgbotNote Added: 0029311
2010-07-14 15:40hgbotStatusscheduled => resolved
2010-07-14 15:40hgbotResolutionopen => fixed
2010-07-14 15:40hgbotFixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/8b98f543308c77448f62386fb1dfdb04b61fbd52 [^]
2010-07-14 15:40harikrishnanNote Added: 0029312
2010-07-15 10:07sureshbabuNote Added: 0029327
2010-07-15 10:07sureshbabuStatusresolved => closed
2010-07-15 10:18hudsonbotCheckin
2010-07-15 10:18hudsonbotNote Added: 0029331
2010-07-16 00:00anonymoussf_bug_id0 => 3030266

Notes
(0029311)
hgbot   
2010-07-14 15:40   
Repository: erp/devel/pi
Changeset: 8b98f543308c77448f62386fb1dfdb04b61fbd52
Author: Harikrishnan Raja <harikrishnan.raja <at> openbravo.com>
Date: Wed Jul 14 19:09:09 2010 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/8b98f543308c77448f62386fb1dfdb04b61fbd52 [^]

Fixes Issue 13484: User created on Initial Organization Setup has Client Admin role

---
M src/org/openbravo/erpCommon/ad_forms/InitialOrgSetup.java
M src/org/openbravo/erpCommon/ad_forms/InitialOrgSetup_data.xsql
---
(0029312)
harikrishnan   
2010-07-14 15:40   
Steps to test:
*Create a client.
*Login in to Client created User and create a new organization.
*While creating the new organization a user is created with the new user role.
*The role user level is organization level.

Root Cause:
*Before the User created by organization is assigned with the Client user role.

Impact:

*Their is impact through out the core functionality of the organization.They are tested.
(0029327)
sureshbabu   
2010-07-15 10:07   
verified.
(0029331)
hudsonbot   
2010-07-15 10:18   
A changeset related to this issue has been promoted to main after passing a series of tests and an OBX has been generated:

Changeset: http://code.openbravo.com/erp/devel/main/rev/8b98f543308c [^]
Merge Changeset: http://code.openbravo.com/erp/devel/main/rev/33fb2a504aa2 [^]
Tests: http://builds.openbravo.com/view/int/ [^]
OBX: http://builds.openbravo.com/erp/core/obx/OpenbravoERP-2.50CI.17884.obx [^]