Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0014947Openbravo ERPA. Platformpublic2010-10-20 19:542010-12-21 00:00
dmitry_mezentsev 
adrianromero 
normaltrivialalways
closedfixed 
5
2.50MP22 
3.0RC3 
Core
No
0014947: Clean System Admin Role from the entities (Windows, Reports and so on) it should not have access to
If you access OB with a System Admin role you can see that it has an access to the Functional entities - Procurement Management, Sales Management, Master Data and so on, while it should not be the case.
System Admin should have an access only to the System Level (installation wide) specific components. IMO - Application Dictionary, General Setup.
Setup Proper Data Access Level for the mentioned above entities (Client/Org or Org).
No tags attached.
Issue History
2010-10-20 19:54dmitry_mezentsevNew Issue
2010-10-20 19:54dmitry_mezentsevAssigned To => adrianromero
2010-11-04 09:28hgbotCheckin
2010-11-04 09:28hgbotNote Added: 0032386
2010-11-04 09:28hgbotStatusnew => resolved
2010-11-04 09:28hgbotResolutionopen => fixed
2010-11-04 09:28hgbotFixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/5fc875b9ab51e2676103ce2d7d69e62cb651525d [^]
2010-11-04 10:07adrianromeroNote Added: 0032387
2010-11-05 12:45hudsonbotCheckin
2010-11-05 12:45hudsonbotNote Added: 0032450
2010-12-20 19:31psarobeNote Added: 0033328
2010-12-20 19:31psarobeStatusresolved => closed
2010-12-21 00:00anonymoussf_bug_id0 => 3140996

Notes
(0032386)
hgbot   
2010-11-04 09:28   
Repository: erp/devel/pi
Changeset: 5fc875b9ab51e2676103ce2d7d69e62cb651525d
Author: Adrián Romero <adrianromero <at> openbravo.com>
Date: Wed Nov 03 18:11:37 2010 +0100
URL: http://code.openbravo.com/erp/devel/pi/rev/5fc875b9ab51e2676103ce2d7d69e62cb651525d [^]

Fixes issue 0014947: Clean System Admin Role from the entities (Windows, Reports and so on) it should not have access to
It has been changed the Access Level of all reports and processes that appear at System level

---
M src-db/database/sourcedata/AD_PROCESS.xml
---
(0032387)
adrianromero   
2010-11-04 10:07   
* Testing the issue

In a clean Openbravo ERP installation, verify that logged as System Administrator Only appear in the menu the following options:

* Application Dictionary
** (All)
* General Setup
** (All)
* Master Data Management
** Send Mail Text
** Business Partner Setup
*** Title
*** Areas of Interest
** Product Setup
*** Unit of Measure
** Import Data
*** Import Loader Format
*** Import File Loader
*** Import Products
*** Import Business Partner
*** Import Account
*** Import Orders
*** Import Budget
*** Import Taxes
* Sales Management
** Setup
*** Mail Template
* Financial Management
** Setup
*** Accounting Dimension
*** Accounting Process
*** Account Combination
*** G/L Category
*** Document Type
*** Document Sequence
*** ABC Activity
*** Accounting templates

Verify that other roles have not been modified and continue having the same access to the application.

* Other areas affected

No other areas affected.
(0032450)
hudsonbot   
2010-11-05 12:45   
A changeset related to this issue has been promoted to main after passing a series of tests and an OBX has been generated:

Changeset: http://code.openbravo.com/erp/devel/main/rev/5fc875b9ab51 [^]
Merge Changeset: http://code.openbravo.com/erp/devel/main/rev/f2cf138fa03c [^]
Tests: http://builds.openbravo.com/view/int/ [^]
OBX: http://builds.openbravo.com/erp/core/obx/OpenbravoERP-2.50CI.18797.obx [^]
(0033328)
psarobe   
2010-12-20 19:31   
Tested working fine