Openbravo Issue Tracking System - Openbravo ERP |
View Issue Details |
|
ID | Project | Category | View Status | Date Submitted | Last Update |
0057255 | Openbravo ERP | C. Security | public | 2024-10-03 09:07 | 2025-03-03 12:32 |
|
Reporter | eduardo_Argal | |
Assigned To | Triage Platform Base | |
Priority | immediate | Severity | major | Reproducibility | always |
Status | new | Resolution | open | |
Platform | | OS | 5 | OS Version | |
Product Version | pi | |
Target Version | PR24Q4.2 | Fixed in Version | | |
Merge Request Status | approved |
Review Assigned To | |
OBNetwork customer | No |
Web browser | |
Modules | Core |
Support ticket | |
Regression level | Production - Confirmed Stable |
Regression date | |
Regression introduced in release | |
Regression introduced by commit | |
Triggers an Emergency Pack | No |
|
Summary | 0057255: A user with a not Manual role can access, edit and create transactions in any organization |
Description | A user with a not Manual role can access, edit and create transactions in any organization even if the organization access is limited to one store. |
Steps To Reproduce | 1) Log as Orhi Store User
2) Go to Purchase Order Window
3) Create a new record
4) Mind that the organization combo displays the full list of organization when it should just display the organizations defined in the Org Access tab for his/her role
5) change the configuration for the role to Manual
6) Repeat the steps and mind that now the organizatiuon combo works properly |
Proposed Solution | Check previous behavior:
- How is the org access provided? Only on role creation? On update as well?
Check workaround:
- Ensure that disabling the role_org record works as expected |
Additional Information | |
Tags | No tags attached. |
Relationships | blocks | defect | 0056631 | pi | closed | AugustoMauch | A user with a not Manual role can access, edit and create transactions in any organization |
|
Attached Files | |
|
Issue History |
Date Modified | Username | Field | Change |
2024-11-22 11:13 | AugustoMauch | Type | defect => backport |
2024-11-22 11:13 | AugustoMauch | Target Version | pi => PR24Q4 |
2024-11-28 17:50 | AugustoMauch | Target Version | PR24Q4 => PR24Q4.1 |
2025-02-21 09:12 | AugustoMauch | Note Added: 0176005 | |
2025-02-21 09:12 | AugustoMauch | Note Added: 0176006 | |
2025-02-21 09:12 | AugustoMauch | Status | scheduled => resolved |
2025-02-21 09:12 | AugustoMauch | Fixed in SCM revision | => https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/commit/e5fb01a0a2ae195cb818f478e91b40024ae03f72 [^] |
2025-02-21 09:12 | AugustoMauch | Resolution | open => fixed |
2025-02-21 09:12 | AugustoMauch | Status | resolved => closed |
2025-02-27 09:17 | hgbot | Merge Request Status | => open |
2025-02-27 09:17 | hgbot | Note Added: 0176191 | |
2025-02-27 09:19 | hgbot | Merge Request Status | open => approved |
2025-02-27 09:20 | hgbot | Note Added: 0176193 | |
2025-02-27 09:21 | AugustoMauch | Status | closed => new |
2025-02-27 09:21 | AugustoMauch | Resolution | fixed => open |
2025-03-03 12:32 | AugustoMauch | Target Version | PR24Q4.1 => PR24Q4.2 |