Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0013484
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] 01. General setupmajoralways2010-05-31 13:082010-07-16 00:00
ReporterrafarodaView Statuspublic 
Assigned Toharikrishnan 
PriorityhighResolutionfixedFixed in Version
StatusclosedFix in branchFixed in SCM revision8b98f543308c
ProjectionnoneETAnoneTarget Version2.50MP20
OSLinux 32 bitDatabasePostgreSQLJava version1.5
OS VersionUbuntu 7.10Database version8.3Ant version1.7
Product Version2.50MP17SCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0013484: User created on Initial Organization Setup has Client Admin role

DescriptionOn Initial Organization Setup a user is created: it is supposed to be the Organization administrator. Nevertheless, this user is automatically given a Client Administrator role.

This could be a security hole specially when different organizations are different companies.
Steps To Reproduce1) Perform an Initial Client Setup http://wiki.openbravo.com/wiki/ERP/2.50/Configuration_Manual/Modeling_your_enterprise#Setting_up_a_client [^]
2) Perform an Initial Organization Setup http://wiki.openbravo.com/wiki/ERP/2.50/Configuration_Manual/Modeling_your_enterprise#Setting_up_an_organization [^]
3) Navigate to General Setup || Security || User and select the Organization User created.
4) In user Roles tab see that the user has been assigned the Client Admin role.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to defect 0013483 closedpsarobe Role System Administrator visible in Entity Roles 

-  Notes
(0029311)
hgbot (developer)
2010-07-14 15:40

Repository: erp/devel/pi
Changeset: 8b98f543308c77448f62386fb1dfdb04b61fbd52
Author: Harikrishnan Raja <harikrishnan.raja <at> openbravo.com>
Date: Wed Jul 14 19:09:09 2010 +0530
URL: http://code.openbravo.com/erp/devel/pi/rev/8b98f543308c77448f62386fb1dfdb04b61fbd52 [^]

Fixes Issue 13484: User created on Initial Organization Setup has Client Admin role

---
M src/org/openbravo/erpCommon/ad_forms/InitialOrgSetup.java
M src/org/openbravo/erpCommon/ad_forms/InitialOrgSetup_data.xsql
---
(0029312)
harikrishnan (reporter)
2010-07-14 15:40

Steps to test:
*Create a client.
*Login in to Client created User and create a new organization.
*While creating the new organization a user is created with the new user role.
*The role user level is organization level.

Root Cause:
*Before the User created by organization is assigned with the Client user role.

Impact:

*Their is impact through out the core functionality of the organization.They are tested.
(0029327)
sureshbabu (reporter)
2010-07-15 10:07

verified.
(0029331)
hudsonbot (developer)
2010-07-15 10:18

A changeset related to this issue has been promoted to main after passing a series of tests and an OBX has been generated:

Changeset: http://code.openbravo.com/erp/devel/main/rev/8b98f543308c [^]
Merge Changeset: http://code.openbravo.com/erp/devel/main/rev/33fb2a504aa2 [^]
Tests: http://builds.openbravo.com/view/int/ [^]
OBX: http://builds.openbravo.com/erp/core/obx/OpenbravoERP-2.50CI.17884.obx [^]

- Issue History
Date Modified Username Field Change
2010-05-31 13:08 rafaroda New Issue
2010-05-31 13:08 rafaroda Assigned To => psarobe
2010-05-31 13:08 rafaroda Relationship added related to 0013483
2010-06-28 11:06 psarobe Status new => scheduled
2010-06-28 11:06 psarobe Assigned To psarobe => adrianromero
2010-06-28 11:06 psarobe fix_in_branch => pi
2010-07-05 12:48 jonalegriaesarte Target Version => 2.50MP21
2010-07-05 12:48 jonalegriaesarte fix_in_branch pi =>
2010-07-05 12:50 jonalegriaesarte Target Version 2.50MP21 => 2.50MP20
2010-07-14 15:31 harikrishnan Assigned To adrianromero => harikrishnan
2010-07-14 15:40 hgbot Checkin
2010-07-14 15:40 hgbot Note Added: 0029311
2010-07-14 15:40 hgbot Status scheduled => resolved
2010-07-14 15:40 hgbot Resolution open => fixed
2010-07-14 15:40 hgbot Fixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/8b98f543308c77448f62386fb1dfdb04b61fbd52 [^]
2010-07-14 15:40 harikrishnan Note Added: 0029312
2010-07-15 10:07 sureshbabu Note Added: 0029327
2010-07-15 10:07 sureshbabu Status resolved => closed
2010-07-15 10:18 hudsonbot Checkin
2010-07-15 10:18 hudsonbot Note Added: 0029331
2010-07-16 00:00 anonymous sf_bug_id 0 => 3030266


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker