Openbravo Issue Tracking System - Openbravo ERP | ||||||||||||
View Issue Details | ||||||||||||
ID | Project | Category | View Status | Date Submitted | Last Update | |||||||
0002398 | Openbravo ERP | C. Security | public | 2007-12-20 14:42 | 2008-07-08 18:43 | |||||||
Reporter | roklenardic | |||||||||||
Assigned To | alostale | |||||||||||
Priority | normal | Severity | minor | Reproducibility | always | |||||||
Status | closed | Resolution | fixed | |||||||||
Platform | OS | 5 | OS Version | |||||||||
Product Version | ||||||||||||
Target Version | Fixed in Version | 2.40beta | ||||||||||
Merge Request Status | ||||||||||||
Review Assigned To | ||||||||||||
OBNetwork customer | No | |||||||||||
Web browser | ||||||||||||
Modules | Core | |||||||||||
Support ticket | ||||||||||||
Regression level | ||||||||||||
Regression date | ||||||||||||
Regression introduced in release | ||||||||||||
Regression introduced by commit | ||||||||||||
Triggers an Emergency Pack | No | |||||||||||
Summary | 0002398: Delete key in Relation view | |||||||||||
Description | When in relation mode/view of a window/tab that has read-only privileges, one can still press the delete key and delete a record even though the button in the toolbar for deleting it does not exist (clearly since it is a read only window). This seems to be a major security/privileges issues since people that do not have delete privileges can delete record in relation view or windows/tabs that are defined as read only still allow deletion. Ubuntu Oracle XE tomcat 5.5 firefox 2 | |||||||||||
Steps To Reproduce | ||||||||||||
Proposed Solution | ||||||||||||
Additional Information | ||||||||||||
Tags | No tags attached. | |||||||||||
Relationships |
| |||||||||||
Attached Files | ||||||||||||
Issue History | ||||||||||||
Date Modified | Username | Field | Change | |||||||||
2008-07-08 18:43 | plujan | Status | resolved => closed | |||||||||
2008-07-08 18:43 | plujan | Fixed in Version | 2.40alpha-r2 => 2.40beta |
Notes | |||||
|
|||||
|
|