Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0018389Openbravo ERPA. Platformpublic2011-08-30 16:242011-10-20 11:32
rgoris 
iperdomo 
urgentmajoralways
closedunable to reproduce 
5
 
3.0MP5 
Core
No
0018389: Google Account login - security issue
Logging in using your Google account is cool. However, there are a couple of issues that keep it from being very cool.

Security: when activating this feature and you happen to have somebody elseĀ“s Google account activated in the same browser, you accidentally would associate their account to your Openbravo!
Log in with somebody else Google account
In the same browser, associate OB to the Google login
Let the user confirm (and re-login) to the desired google account before actually creating the association.
No tags attached.
related to defect 00183913.0MP5 closed dbaz Google Account login - tons of typos 
Issue History
2011-08-30 16:24rgorisNew Issue
2011-08-30 16:24rgorisAssigned To => alostale
2011-08-30 16:24rgorisModules => Core
2011-08-30 16:57rgorisRelationship addedrelated to 0018391
2011-08-30 16:58rgorisStatusnew => scheduled
2011-09-08 18:54rgorisPrioritynormal => urgent
2011-09-27 13:03alostaleTarget Version3.0MP4 => 3.0MP5
2011-09-28 22:19alostaleAssigned Toalostale => iperdomo
2011-09-29 08:39iperdomoNote Added: 0041362
2011-09-29 08:39iperdomoStatusscheduled => feedback
2011-10-20 11:32rgorisStatusfeedback => closed
2011-10-20 11:32rgorisResolutionopen => unable to reproduce

Notes
(0041362)
iperdomo   
2011-09-29 08:39   
If you are logged in in Google and you try to associate the account, you will clearly see that the Openbravo system is trying to access your account, Google accounts will ask you and you can _reject_ it.