Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0058045Openbravo ERPC. Securitypublic2024-10-03 09:072025-03-03 13:59
eduardo_Argal 
Triage Platform Base 
immediatemajoralways
scheduledopen 
5
pi 
PR25Q1.1 
approved
No
Core
Production - Confirmed Stable
2023-10-17
PR24Q1
No
0058045: A user with a not Manual role can access, edit and create transactions in any organization
A user with a not Manual role can access, edit and create transactions in any organization even if the organization access is limited to one store.
1) Log as Orhi Store User
2) Go to Purchase Order Window
3) Create a new record
4) Mind that the organization combo displays the full list of organization when it should just display the organizations defined in the Org Access tab for his/her role
5) change the configuration for the role to Manual
6) Repeat the steps and mind that now the organizatiuon combo works properly
Workaround: it is possible to prevent access to organizations for automatic roles by creating those roles as disable (Active = false) in the Role > Org Access tab.
No tags attached.
blocks defect 0056631pi closed AugustoMauch A user with a not Manual role can access, edit and create transactions in any organization 
Issue History
2025-02-21 08:35AugustoMauchTypedefect => backport
2025-02-21 08:35AugustoMauchTarget Versionpi => PR25Q1
2025-03-03 13:59AugustoMauchTarget VersionPR25Q1 => PR25Q1.1

There are no notes attached to this issue.