Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0057255Openbravo ERPC. Securitypublic2024-10-03 09:072024-11-22 11:13
eduardo_Argal 
Triage Platform Base 
immediatemajoralways
scheduledopen 
5
pi 
PR24Q4 
Core
Production - Confirmed Stable
No
0057255: A user with a not Manual role can access, edit and create transactions in any organization
A user with a not Manual role can access, edit and create transactions in any organization even if the organization access is limited to one store.
1) Log as Orhi Store User
2) Go to Purchase Order Window
3) Create a new record
4) Mind that the organization combo displays the full list of organization when it should just display the organizations defined in the Org Access tab for his/her role
5) change the configuration for the role to Manual
6) Repeat the steps and mind that now the organizatiuon combo works properly
Check previous behavior:
- How is the org access provided? Only on role creation? On update as well?

Check workaround:
- Ensure that disabling the role_org record works as expected
No tags attached.
blocks defect 0056631pi scheduled Triage Platform Base A user with a not Manual role can access, edit and create transactions in any organization 
Issue History
2024-11-22 11:13AugustoMauchTypedefect => backport
2024-11-22 11:13AugustoMauchTarget Versionpi => PR24Q4

There are no notes attached to this issue.