Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0002398
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] C. Securityminoralways2007-12-20 14:422008-07-08 18:43
ReporterroklenardicView Statuspublic 
Assigned Toalostale 
PrioritynormalResolutionfixedFixed in Version2.40beta
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Status
Review Assigned To
OBNetwork customerNo
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0002398: Delete key in Relation view

DescriptionWhen in relation mode/view of a window/tab that has read-only privileges, one can still press the delete key and delete a record even though the button in the toolbar for deleting it does not exist (clearly since it is a read only window).

This seems to be a major security/privileges issues since people that do not have delete privileges can delete record in relation view or windows/tabs that are defined as read only still allow deletion.

Ubuntu
Oracle XE
tomcat 5.5
firefox 2
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
depends on backport 0003626 closedalostale Delete key in Relation view 

-  Notes
(0005987)
user71
2005-06-01 00:00
edited on: 2008-06-12 09:43

This bug was originally reported in SourceForge bug tracker and then migrated to Mantis.

You can see the original bug report in:
https://sourceforge.net/support/tracker.php?aid=1854877 [^]

- Issue History
Date Modified Username Field Change
2008-07-08 18:43 plujan Status resolved => closed
2008-07-08 18:43 plujan Fixed in Version 2.40alpha-r2 => 2.40beta


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker