Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0054921
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[POS2] Coremajorhave not tried2024-03-12 10:592024-03-12 11:01
ReportercaristuView Statuspublic 
Assigned ToTriage Platform Base 
PrioritynormalResolutionopenFixed in Version
StatusnewFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Review Assigned To
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0054921: User actions defined in standalone infrastructure modules cannot be securized

DescriptionUser actions defined in standalone infrastructure modules cannot be securized.
Steps To Reproduce0) In a POS2 environment, install the org.openbravo.authentication.webauthn. This is an "infrastructure module".
1) Go to the [Role] window, select a role
2) Go to the [User Action Access] subtab and create a new record
   - User Action: "Register User"
   - active: false
3) Login in the POS with the role selected in step 1)
4) Click in the user button at the top-right part of the window. In the popup that is opened, note that the "WebAuthn Register" button is available (not disabled) although we should not have access to the "Register User" user action that this button triggers.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to defect 0054737 closedAugustoMauch Build process improvement: include missing dependencies, support standalone infrastructure modules 

-  Notes
(0162010)
caristu (manager)
2024-03-12 11:01

This is happening because standalone infrastructure modules are not being taken into account here[1]. User actions that belong to this kind of modules should also be taken into account.

[1] https://gitlab.com/openbravo/product/pmods/org.openbravo.core2/-/blob/master/src/org/openbravo/core2/login/GrantedUserActionsProvider.java?ref_type=heads#L100 [^]

- Issue History
Date Modified Username Field Change
2024-03-12 10:59 caristu New Issue
2024-03-12 10:59 caristu Assigned To => Triage Platform Base
2024-03-12 10:59 caristu Triggers an Emergency Pack => No
2024-03-12 11:00 caristu Relationship added related to 0054737
2024-03-12 11:01 caristu Note Added: 0162010
2024-03-12 11:01 caristu Summary User actions defined in infrastructure modules cannot be securized => User actions defined in standalone infrastructure modules cannot be securized
2024-03-12 11:01 caristu Description Updated View Revisions


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker