Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0057513
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Openbravo ERP] A. Platformmajoralways2024-12-19 21:582024-12-19 21:58
ReporteregoitzView Statuspublic 
Assigned ToTriage Platform Base 
PriorityurgentResolutionopenFixed in Version
StatusnewFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0057513: The session is modified when using the POS and opening a new tab with the url with the backoffice URL even when not access

DescriptionWhen using a role defined as restrict backoffice access to yes,
if you are using the POS and you open a new tab with the backoffice URL, you get a message saying that you don't have access, but the ad_session row linked to the user/session you were using is changed from OB_POS to S (Sucess).
The loging_status should be keep as OB_POS becuas the access to BO is not allowed/done.

This is affecting the invoicing of our customers as we are invoicing them in SaaS based on the users doing a Successful login in the backoffice.
Steps To Reproduce- Define the vallblancauser role as "restrict backoffice access" to Y
- Access to the pos with the valblanca user and vallblancaruser role.
- See in another profile, in the session window as system admin, that there is a session with login_status OB-POS
- ON the previous profile where the pos login was done, open a new tab putting the URL of the backoffice
- You get a error message saying that you can access to the backoffice
- Check on the session that the Login_status has changed to Sucess
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]

-  Notes
There are no notes attached to this issue.

- Issue History
Date Modified Username Field Change
2024-12-19 21:58 egoitz New Issue
2024-12-19 21:58 egoitz Assigned To => Triage Platform Base
2024-12-19 21:58 egoitz Modules => Core
2024-12-19 21:58 egoitz Triggers an Emergency Pack => No


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker