Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0018389
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] A. Platformmajoralways2011-08-30 16:242011-10-20 11:32
ReporterrgorisView Statuspublic 
Assigned Toiperdomo 
PriorityurgentResolutionunable to reproduceFixed in Version
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version3.0MP5
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0018389: Google Account login - security issue

DescriptionLogging in using your Google account is cool. However, there are a couple of issues that keep it from being very cool.

Security: when activating this feature and you happen to have somebody else´s Google account activated in the same browser, you accidentally would associate their account to your Openbravo!
Steps To ReproduceLog in with somebody else Google account
In the same browser, associate OB to the Google login
Proposed SolutionLet the user confirm (and re-login) to the desired google account before actually creating the association.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to defect 00183913.0MP5 closeddbaz Google Account login - tons of typos 

-  Notes
(0041362)
iperdomo (reporter)
2011-09-29 08:39

If you are logged in in Google and you try to associate the account, you will clearly see that the Openbravo system is trying to access your account, Google accounts will ask you and you can _reject_ it.

- Issue History
Date Modified Username Field Change
2011-08-30 16:24 rgoris New Issue
2011-08-30 16:24 rgoris Assigned To => alostale
2011-08-30 16:24 rgoris Modules => Core
2011-08-30 16:57 rgoris Relationship added related to 0018391
2011-08-30 16:58 rgoris Status new => scheduled
2011-09-08 18:54 rgoris Priority normal => urgent
2011-09-27 13:03 alostale Target Version 3.0MP4 => 3.0MP5
2011-09-28 22:19 alostale Assigned To alostale => iperdomo
2011-09-29 08:39 iperdomo Note Added: 0041362
2011-09-29 08:39 iperdomo Status scheduled => feedback
2011-10-20 11:32 rgoris Status feedback => closed
2011-10-20 11:32 rgoris Resolution open => unable to reproduce


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker