Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0024858
TypeCategorySeverityReproducibilityDate SubmittedLast Update
feature request[Openbravo ERP] A. Platformminoralways2013-10-01 11:592014-02-12 18:28
ReportercaristuView Statuspublic 
Assigned Todbaz 
PriorityhighResolutionfixedFixed in Version3.0PR14Q2
StatusclosedFix in branchFixed in SCM revision267df0f85b0e
ProjectionnoneETAnoneTarget Version3.0PR14Q2
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Review Assigned Toalostale
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0024858: Restrict access to REST web services

DescriptionThe Openbravo REST web services use the same access/authorizations as the standard Openbravo application, so if a role is able to access a to the information of a table, the entity associated to this table is accessible for this role through its corresponding REST webservice.

It would be nice to have a mechanism to allow us to restrict access just to the web service for a particular role and at the same time this role would be able access to the window.
Steps To Reproduce.
TagsNo tags attached.
Attached Files? file icon wsRolSec.export [^] (22,570 bytes) 2013-12-19 13:51

- Relationships Relation Graph ] Dependency Graph ]
related to defect 0026566 closedguillermogil error is returned when a call to web service is done and the role used don't have permission to Role and User window 

-  Notes
(0063538)
hgbot (developer)
2014-01-20 14:51

Repository: erp/devel/pi
Changeset: 267df0f85b0e2084cbe4f0555be9552615ec17f0
Author: David Baz Fayos <david.baz <at> openbravo.com>
Date: Mon Jan 20 14:50:37 2014 +0100
URL: http://code.openbravo.com/erp/devel/pi/rev/267df0f85b0e2084cbe4f0555be9552615ec17f0 [^]

Fixed issue 24858: Added 'Is Web Service Enabled' field to 'Role' window

---
M modules/org.openbravo.service.json/src/org/openbravo/service/json/JsonRestServlet.java
M referencedata/sampledata/F_B_International_Group/AD_ROLE.xml
M referencedata/sampledata/QA_Testing/AD_ROLE.xml
M src-db/database/model/tables/AD_ROLE.xml
M src-db/database/sourcedata/AD_COLUMN.xml
M src-db/database/sourcedata/AD_ELEMENT.xml
M src-db/database/sourcedata/AD_FIELD.xml
M src/org/openbravo/service/web/BaseWebServiceServlet.java
---
(0063734)
alostale (manager)
2014-01-28 08:06

Code reviewed + tested for:
-Standard XML Web Services
-Standard JSON Web Services
-Manually implemented Web Services
(0064092)
hudsonbot (developer)
2014-02-12 18:28

A changeset related to this issue has been promoted main and to the
Central Repository, after passing a series of tests.

Promotion changeset: https://code.openbravo.com/erp/devel/main/rev/d1a5bb862230 [^]
Maturity status: Test

- Issue History
Date Modified Username Field Change
2013-10-01 11:59 caristu New Issue
2013-10-01 11:59 caristu Assigned To => AugustoMauch
2013-10-01 11:59 caristu Modules => Core
2013-10-01 11:59 caristu Triggers an Emergency Pack => No
2013-12-18 18:00 dbaz Assigned To AugustoMauch => dbaz
2013-12-18 18:01 dbaz Issue Monitored: alostale
2013-12-18 18:01 dbaz Review Assigned To => alostale
2013-12-18 18:02 dbaz Issue Monitored: dbaz
2013-12-18 18:02 dbaz File Added: wsRolSec.diff
2013-12-19 11:43 dbaz File Deleted: wsRolSec.diff
2013-12-19 11:43 dbaz File Added: wsRolSec.export
2013-12-19 13:51 dbaz File Deleted: wsRolSec.export
2013-12-19 13:51 dbaz File Added: wsRolSec.export
2014-01-20 08:24 alostale Target Version => 3.0MP32
2014-01-20 14:51 hgbot Checkin
2014-01-20 14:51 hgbot Note Added: 0063538
2014-01-20 14:51 hgbot Status new => resolved
2014-01-20 14:51 hgbot Resolution open => fixed
2014-01-20 14:51 hgbot Fixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/267df0f85b0e2084cbe4f0555be9552615ec17f0 [^]
2014-01-28 08:06 alostale Note Added: 0063734
2014-01-28 08:06 alostale Status resolved => closed
2014-01-28 08:06 alostale Fixed in Version => 3.0MP32
2014-02-12 18:28 hudsonbot Checkin
2014-02-12 18:28 hudsonbot Note Added: 0064092
2014-05-16 12:30 guillermogil Relationship added related to 0026566


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker