Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0002958
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] C. Securityminoralways2008-05-06 14:512008-06-19 19:26
Reporteruser71View Statuspublic 
Assigned Touser71 
PrioritynormalResolutionfixedFixed in Version2.40alpha-r2
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Status
Review Assigned To
OBNetwork customerNo
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0002958: Can delete records from client 0 without access permission

DescriptionProblem:
  - For delete in datagrids always has permision on records from client 0.

Steps:
  - With role System Administrator create a user.
  - Change role to and other with less priviliges(e.g. role b)
  - Go to users and in edit mode you can't delete the record, but in RELATIONAL mode you CAN DELETE the record.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]

-  Notes
(0003668)
user71
2008-05-06 14:58
edited on: 2008-06-12 09:26

Logged In: YES
user_id=1964080
Originator: YES

Fixed since revision 3967 in the trunk

  - Added windowId and accessLevel control for delete in datagrids

  Change
    Utility.getContext(this, vars, "#User_Client", "win")
  into
    Utility.getContext(this, vars, "#User_Client", WindowId, accessLevel)
(0006547)
user71
2005-06-01 00:00
edited on: 2008-06-12 09:43

This bug was originally reported in SourceForge bug tracker and then migrated to Mantis.

You can see the original bug report in:
https://sourceforge.net/support/tracker.php?aid=1958704 [^]

- Issue History
Date Modified Username Field Change
2008-06-19 19:26 psarobe Status resolved => closed


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker