Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0025023Openbravo ERPC. Securitypublic2013-10-25 11:542014-02-15 02:00
egoitz 
shankarb 
immediatecriticalhave not tried
closedfixed 
5
 
3.0PR14Q23.0PR14Q2 
AugustoMauch
No
Core
No
0025023: Security problem on the alert window
Security problem on the alert window
Check the code
No tags attached.
Issue History
2013-10-25 11:54egoitzNew Issue
2013-10-25 11:54egoitzAssigned To => AugustoMauch
2013-10-25 11:54egoitzModules => Core
2013-10-25 11:54egoitzOBNetwork customer => No
2013-10-25 11:54egoitzTriggers an Emergency Pack => No
2014-01-07 08:33alostaleTarget Version => 3.0MP32
2014-01-27 07:24shankarbAssigned ToAugustoMauch => shankarb
2014-01-27 07:24shankarbStatusnew => scheduled
2014-01-27 07:24shankarbfix_in_branch => pi
2014-01-27 10:15shankarbIssue Monitored: AugustoMauch
2014-01-27 10:15shankarbReview Assigned To => AugustoMauch
2014-01-27 10:15shankarbfix_in_branchpi =>
2014-01-27 10:16hgbotCheckin
2014-01-27 10:16hgbotNote Added: 0063704
2014-01-27 10:16hgbotStatusscheduled => resolved
2014-01-27 10:16hgbotResolutionopen => fixed
2014-01-27 10:16hgbotFixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/fcc10a50bab69688bb2d59f51addd93957ec1980 [^]
2014-01-28 12:50AugustoMauchNote Added: 0063748
2014-01-28 12:50AugustoMauchStatusresolved => new
2014-01-28 12:50AugustoMauchResolutionfixed => open
2014-01-29 08:38hgbotCheckin
2014-01-29 08:38hgbotNote Added: 0063767
2014-01-29 08:38hgbotStatusnew => resolved
2014-01-29 08:38hgbotResolutionopen => fixed
2014-01-29 08:38hgbotFixed in SCM revisionhttp://code.openbravo.com/erp/devel/pi/rev/fcc10a50bab69688bb2d59f51addd93957ec1980 [^] => http://code.openbravo.com/erp/devel/pi/rev/8392986ae06fdeb92e49f9b6436068c1c77c150e [^]
2014-01-30 07:34hgbotCheckin
2014-01-30 07:34hgbotNote Added: 0063797
2014-02-12 18:29hudsonbotCheckin
2014-02-12 18:29hudsonbotNote Added: 0064115
2014-02-12 18:29hudsonbotCheckin
2014-02-12 18:29hudsonbotNote Added: 0064131
2014-02-12 18:29hudsonbotCheckin
2014-02-12 18:29hudsonbotNote Added: 0064137
2014-02-13 15:50hgbotCheckin
2014-02-13 15:50hgbotNote Added: 0064229
2014-02-13 17:10AugustoMauchNote Added: 0064234
2014-02-13 17:11AugustoMauchStatusresolved => closed
2014-02-13 17:11AugustoMauchFixed in Version => 3.0MP32
2014-02-15 02:00hudsonbotCheckin
2014-02-15 02:00hudsonbotNote Added: 0064274

Notes
(0063704)
hgbot   
2014-01-27 10:16   
Repository: erp/devel/pi
Changeset: fcc10a50bab69688bb2d59f51addd93957ec1980
Author: Shankar Balachandran <shankar.balachandran <at> openbravo.com>
Date: Mon Jan 27 14:44:00 2014 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/fcc10a50bab69688bb2d59f51addd93957ec1980 [^]

Fixes Issue 0025023: Security problem on the alert window

Allow only read only transactions when executing alerts.

---
M src/org/openbravo/erpCommon/ad_callouts/SL_AlertRule_SQL.java
M src/org/openbravo/erpCommon/ad_process/AlertProcess.java
---
(0063748)
AugustoMauch   
2014-01-28 12:50   
Reopened because fix is incomplete
(0063767)
hgbot   
2014-01-29 08:38   
Repository: erp/devel/pi
Changeset: 8392986ae06fdeb92e49f9b6436068c1c77c150e
Author: Shankar Balachandran <shankar.balachandran <at> openbravo.com>
Date: Wed Jan 29 13:07:07 2014 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/8392986ae06fdeb92e49f9b6436068c1c77c150e [^]

Fixes Issue 0025023: Security problem on the alert window

Execute alerts only if it startsWith SELECT.

---
M src/org/openbravo/erpCommon/ad_process/AlertProcess.java
---
(0063797)
hgbot   
2014-01-30 07:34   
Repository: erp/devel/pi
Changeset: 3c7807526be6c6d687563262e34d5f4ce3c56c86
Author: Shankar Balachandran <shankar.balachandran <at> openbravo.com>
Date: Thu Jan 30 12:02:52 2014 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/3c7807526be6c6d687563262e34d5f4ce3c56c86 [^]

Related to Issue 25023: Added error message for alert queries

---
M src/org/openbravo/erpCommon/ad_callouts/SL_AlertRule_SQL.java
M src/org/openbravo/erpCommon/ad_process/AlertProcess.java
---
(0064115)
hudsonbot   
2014-02-12 18:29   
A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: https://code.openbravo.com/erp/devel/main/rev/d1a5bb862230 [^]
Maturity status: Test
(0064131)
hudsonbot   
2014-02-12 18:29   
A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: https://code.openbravo.com/erp/devel/main/rev/d1a5bb862230 [^]
Maturity status: Test
(0064137)
hudsonbot   
2014-02-12 18:29   
A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: https://code.openbravo.com/erp/devel/main/rev/d1a5bb862230 [^]
Maturity status: Test
(0064229)
hgbot   
2014-02-13 15:50   
Repository: erp/devel/pi
Changeset: e2e4ee24620210d87432677c04434577ba5bdcbb
Author: Shankar Balachandran <shankar.balachandran <at> openbravo.com>
Date: Thu Feb 13 20:19:32 2014 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/e2e4ee24620210d87432677c04434577ba5bdcbb [^]

Related to Issue 0025023: Added missing message definition.

---
M src-db/database/sourcedata/AD_MESSAGE.xml
---
(0064234)
AugustoMauch   
2014-02-13 17:10   
Code reviewed and verified in pi@b6dad5dc6d68
(0064274)
hudsonbot   
2014-02-15 02:00   
A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: https://code.openbravo.com/erp/devel/main/rev/90b0b23defc9 [^]
Maturity status: Test