Openbravo Issue Tracking System - Openbravo ERP |
| View Issue Details |
|
| ID | Project | Category | View Status | Date Submitted | Last Update |
| 0057255 | Openbravo ERP | C. Security | public | 2024-10-03 09:07 | 2025-03-03 12:32 |
|
| Reporter | eduardo_Argal | |
| Assigned To | Triage Platform Base | |
| Priority | immediate | Severity | major | Reproducibility | always |
| Status | new | Resolution | open | |
| Platform | | OS | 5 | OS Version | |
| Product Version | pi | |
| Target Version | PR24Q4.2 | Fixed in Version | | |
| Merge Request Status | approved |
| Review Assigned To | |
| OBNetwork customer | No |
| Web browser | |
| Modules | Core |
| Support ticket | |
| Regression level | Production - Confirmed Stable |
| Regression date | |
| Regression introduced in release | |
| Regression introduced by commit | |
| Triggers an Emergency Pack | No |
|
| Summary | 0057255: A user with a not Manual role can access, edit and create transactions in any organization |
| Description | A user with a not Manual role can access, edit and create transactions in any organization even if the organization access is limited to one store. |
| Steps To Reproduce | 1) Log as Orhi Store User
2) Go to Purchase Order Window
3) Create a new record
4) Mind that the organization combo displays the full list of organization when it should just display the organizations defined in the Org Access tab for his/her role
5) change the configuration for the role to Manual
6) Repeat the steps and mind that now the organizatiuon combo works properly |
| Proposed Solution | Check previous behavior:
- How is the org access provided? Only on role creation? On update as well?
Check workaround:
- Ensure that disabling the role_org record works as expected |
| Additional Information | |
| Tags | No tags attached. |
| Relationships | | blocks | defect | 0056631 | pi | closed | AugustoMauch | A user with a not Manual role can access, edit and create transactions in any organization |
|
| Attached Files | |
|
| Issue History |
| Date Modified | Username | Field | Change |
| 2024-11-22 11:13 | AugustoMauch | Type | defect => backport |
| 2024-11-22 11:13 | AugustoMauch | Target Version | pi => PR24Q4 |
| 2024-11-28 17:50 | AugustoMauch | Target Version | PR24Q4 => PR24Q4.1 |
| 2025-02-21 09:12 | AugustoMauch | Note Added: 0176005 | |
| 2025-02-21 09:12 | AugustoMauch | Note Added: 0176006 | |
| 2025-02-21 09:12 | AugustoMauch | Status | scheduled => resolved |
| 2025-02-21 09:12 | AugustoMauch | Fixed in SCM revision | => https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/commit/e5fb01a0a2ae195cb818f478e91b40024ae03f72 [^] |
| 2025-02-21 09:12 | AugustoMauch | Resolution | open => fixed |
| 2025-02-21 09:12 | AugustoMauch | Status | resolved => closed |
| 2025-02-27 09:17 | hgbot | Merge Request Status | => open |
| 2025-02-27 09:17 | hgbot | Note Added: 0176191 | |
| 2025-02-27 09:19 | hgbot | Merge Request Status | open => approved |
| 2025-02-27 09:20 | hgbot | Note Added: 0176193 | |
| 2025-02-27 09:21 | AugustoMauch | Status | closed => new |
| 2025-02-27 09:21 | AugustoMauch | Resolution | fixed => open |
| 2025-03-03 12:32 | AugustoMauch | Target Version | PR24Q4.1 => PR24Q4.2 |