Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0057513Openbravo ERPA. Platformpublic2024-12-19 21:582024-12-19 21:58
egoitz 
Triage Platform Base 
urgentmajoralways
newopen 
5
 
 
Core
No
0057513: The session is modified when using the POS and opening a new tab with the url with the backoffice URL even when not access
When using a role defined as restrict backoffice access to yes,
if you are using the POS and you open a new tab with the backoffice URL, you get a message saying that you don't have access, but the ad_session row linked to the user/session you were using is changed from OB_POS to S (Sucess).
The loging_status should be keep as OB_POS becuas the access to BO is not allowed/done.

This is affecting the invoicing of our customers as we are invoicing them in SaaS based on the users doing a Successful login in the backoffice.
- Define the vallblancauser role as "restrict backoffice access" to Y
- Access to the pos with the valblanca user and vallblancaruser role.
- See in another profile, in the session window as system admin, that there is a session with login_status OB-POS
- ON the previous profile where the pos login was done, open a new tab putting the URL of the backoffice
- You get a error message saying that you can access to the backoffice
- Check on the session that the Login_status has changed to Sucess
No tags attached.
Issue History
2024-12-19 21:58egoitzNew Issue
2024-12-19 21:58egoitzAssigned To => Triage Platform Base
2024-12-19 21:58egoitzModules => Core
2024-12-19 21:58egoitzTriggers an Emergency Pack => No

There are no notes attached to this issue.