Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0002794
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] C. Securityminoralways2008-04-02 10:082009-03-06 12:54
ReporterplujanView Statuspublic 
Assigned Toiperdomo 
PrioritynormalResolutionfixedFixed in Version2.40alpha-r3
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Status
Review Assigned To
OBNetwork customerNo
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0002794: QA-CCV2 Retrieving business partner of other clients

DescriptionDescription:
Using "getCustomer - Request - Get by Id" it is possible to retrieve a customer that belongs to a different client.

Environment:
OS: Windows XP SP2
DB: Oracle XE
Release: OB CCV2 branch (28-03-2008)
Web browser: Mozilla Firefox 2

Steps:
1. Create a new client "NewClient" using Initial Client Setup process
2. Query the database to get all customers
3. Using the "NewClientUser" user, create a XML that queries for a customer that belongs to another client.
4. The resulting XML has data, but it should return null.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]

-  Notes
(0003413)
plujan (viewer)
2008-04-03 23:37
edited on: 2008-06-12 09:25

Logged In: YES
user_id=1759992
Originator: YES

Update:
I can retrieve data also with "getCustomer - GetByNameAndSearchKey" and "getCustomerContact - Request - Get by Id". The "getCustomers - Request - Get all Customers" seems to works fine. I could not test the GetByName and GetBySearchKey but please check it too.
Using the UpdateCustomer, UpdateContact and UpdateLocation, I can modify data that belongs to a different client, which is an issue too.
(0006383)
user71
2005-06-01 00:00
edited on: 2008-06-12 09:43

This bug was originally reported in SourceForge bug tracker and then migrated to Mantis.

You can see the original bug report in:
https://sourceforge.net/support/tracker.php?aid=1931995 [^]

- Issue History
Date Modified Username Field Change
2008-06-19 16:37 psarobe Fixed in Version 2.40alpha-r2 => 2.40alpha-r3
2009-03-06 12:54 psarobe Status resolved => closed


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker