Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0049411
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] A. Platformminorhave not tried2022-05-25 13:142022-11-21 07:02
ReportercaristuView Statuspublic 
Assigned Toguillermogil 
PriorityhighResolutionopenFixed in Version
StatusscheduledFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0049411: Password expiration is not checked in the web service authentication flow

DescriptionPassword expiration is not checked in the default web service authentication flow
Steps To Reproduce1) Go to the user window and mark the "Expired Password" flag for a user
2) Execute a web service call, using the crendentials of the user changed in step 1), for example to: <server_url>/openbravo/ws/dal/Country. ERROR: the user is authorized and the WS request is completed although the user password is expired
Proposed SolutionAdd a password expiration check in the DefaultAuthenticationManager.webServiceAuthenticate method in the same way that it is done for the standard login[1]

[1] https://gitlab.com/openbravo/product/openbravo/-/blob/master/src/org/openbravo/authentication/basic/DefaultAuthenticationManager.java#L153 [^]
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to feature request 00322853.0PR16Q3 closedNaroaIriarte make possible to manually set a user as password expired 
related to feature request 0031796 closedjonibc Extend functionality with the option to define a day limit for the password to be changed 

-  Notes
(0143840)
hgbot (developer)
2022-11-18 17:39

Merge Request created: https://gitlab.com/openbravo/product/openbravo/-/merge_requests/771 [^]

- Issue History
Date Modified Username Field Change
2022-05-25 13:14 caristu New Issue
2022-05-25 13:14 caristu Assigned To => Triage Platform Base
2022-05-25 13:14 caristu Modules => Core
2022-05-25 13:14 caristu Triggers an Emergency Pack => No
2022-05-25 13:16 caristu Steps to Reproduce Updated View Revisions
2022-05-25 13:19 caristu Proposed Solution updated
2022-05-25 13:20 caristu Description Updated View Revisions
2022-05-25 13:22 caristu Proposed Solution updated
2022-05-25 13:23 caristu Proposed Solution updated
2022-05-25 13:29 caristu Relationship added related to 0032285
2022-05-25 13:29 caristu Relationship added related to 0031796
2022-06-23 12:46 shuehner Issue Monitored: shuehner
2022-11-15 06:56 guillermogil Status new => acknowledged
2022-11-18 17:39 hgbot Note Added: 0143840
2022-11-21 07:02 guillermogil Status acknowledged => scheduled
2022-11-21 07:02 guillermogil Assigned To Triage Platform Base => guillermogil


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker