Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0010659
TypeCategorySeverityReproducibilityDate SubmittedLast Update
backport[Openbravo ERP] C. Securitymajoralways2009-09-10 14:462009-10-13 12:11
ReportervillindView Statuspublic 
Assigned Toalostale 
PriorityurgentResolutionfixedFixed in Version2.40MP10
StatusclosedFix in branch2.40Fixed in SCM revisionf09cdd911784
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product Version2.40MP8SCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0010659: Adding a new organization adds org access to manual roles

DescriptionAdding a new organization adds org access to manual roles. This poses a security risk as the access control settings are modifid automatically where they should not be modified.
Steps To Reproduce 1. Have an role with ismanula setting active.
 2. Add a new organization
 3. Relogin
 4. See the "Org Access" tab of the manual role
Proposed SolutionSee the attached patch.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
blocks defect 0010548 closedalostale Adding a new organization adds org access to manual roles 

-  Notes
(0020649)
hgbot (developer)
2009-10-02 08:50

Repository: erp/stable/2.40
Changeset: f09cdd91178477ccedef0127213ea2146065b963
Author: Asier Lostalé <asier.lostale <at> openbravo.com>
Date: Fri Oct 02 08:47:52 2009 +0200
URL: http://code.openbravo.com/erp/stable/2.40/rev/f09cdd91178477ccedef0127213ea2146065b963 [^]

fixed bug 0010659: Adding a new organization adds org access to manual roles

---
M src-db/database/model/triggers/AD_ORG_TRG.xml
---
(0020981)
sureshbabu (reporter)
2009-10-13 12:11

Tested working fine, organization not added to the org access to manual roles

- Issue History
Date Modified Username Field Change
2009-09-18 14:08 rafaroda Type defect => backport
2009-09-18 14:08 rafaroda fix_in_branch => 2.40
2009-10-02 08:50 hgbot Checkin
2009-10-02 08:50 hgbot Note Added: 0020649
2009-10-02 08:50 hgbot Status scheduled => resolved
2009-10-02 08:50 hgbot Resolution open => fixed
2009-10-02 08:50 hgbot Fixed in SCM revision => http://code.openbravo.com/erp/stable/2.40/rev/f09cdd91178477ccedef0127213ea2146065b963 [^]
2009-10-13 12:11 sureshbabu Status resolved => closed
2009-10-13 12:11 sureshbabu Note Added: 0020981
2009-10-13 12:11 sureshbabu Fixed in Version => 2.40MP10


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker