Openbravo Issue Tracking System - Openbravo ERP | |||||
View Issue Details | |||||
ID | Project | Category | View Status | Date Submitted | Last Update |
0002224 | Openbravo ERP | C. Security | public | 2007-11-01 21:28 | 2008-11-26 14:02 |
Reporter | pjuvara | ||||
Assigned To | alostale | ||||
Priority | normal | Severity | minor | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Platform | OS | 5 | OS Version | ||
Product Version | |||||
Target Version | Fixed in Version | 2.40alpha-r2 | |||
Merge Request Status | |||||
Review Assigned To | |||||
OBNetwork customer | No | ||||
Web browser | |||||
Modules | Core | ||||
Support ticket | |||||
Regression level | |||||
Regression date | |||||
Regression introduced in release | |||||
Regression introduced by commit | |||||
Triggers an Emergency Pack | No | ||||
Summary | 0002224: AT235: Users with two clients see transactions in wrong one | ||||
Description | Problem Description =================== A user having access to two clients (client A and client B) can see a transaction created in one client from the other client. Environment =========== 2.35 Acceptance Testing Postgre How To Reproduce ================ In a standard installation with BigBazaar client, create a second client and call it ClientB. In ClientB, create a sales order header and save it. Without logging out, switch role to BigBazaar Admin and navigate to the sales order window. The window behavior is such that it queries back the last transaction queried by the user, regardless of the client context. As a result, the sales order created in ClientB is retrieved in BigBazaar client. Notes ===== This is not a security issue since the user has access to that transaction in the first place, but further attempts to process that transaction might give unpredictable results and cause data corruption. | ||||
Steps To Reproduce | |||||
Proposed Solution | |||||
Additional Information | |||||
Tags | No tags attached. | ||||
Relationships | |||||
Attached Files | |||||
Issue History | |||||
Date Modified | Username | Field | Change | ||
2008-11-26 14:02 | psarobe | Regression testing | => No | ||
2008-11-26 14:02 | psarobe | Status | resolved => closed |
Notes | |||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|