Project:
| View Issue Details[ Jump to Notes ] | [ Issue History ] [ Print ] | |||||||||||
| ID | ||||||||||||
| 0058045 | ||||||||||||
| Type | Category | Severity | Reproducibility | Date Submitted | Last Update | |||||||
| backport | [Openbravo ERP] C. Security | major | always | 2024-10-03 09:07 | 2025-03-03 13:59 | |||||||
| Reporter | eduardo_Argal | View Status | public | |||||||||
| Assigned To | Triage Platform Base | |||||||||||
| Priority | immediate | Resolution | open | Fixed in Version | ||||||||
| Status | scheduled | Fix in branch | Fixed in SCM revision | |||||||||
| Projection | none | ETA | none | Target Version | PR25Q1.1 | |||||||
| OS | Any | Database | Any | Java version | ||||||||
| OS Version | Database version | Ant version | ||||||||||
| Product Version | pi | SCM revision | ||||||||||
| Merge Request Status | approved | |||||||||||
| Review Assigned To | ||||||||||||
| OBNetwork customer | No | |||||||||||
| Web browser | ||||||||||||
| Modules | Core | |||||||||||
| Support ticket | ||||||||||||
| Regression level | Production - Confirmed Stable | |||||||||||
| Regression date | 2023-10-17 | |||||||||||
| Regression introduced in release | PR24Q1 | |||||||||||
| Regression introduced by commit | ||||||||||||
| Triggers an Emergency Pack | No | |||||||||||
| Summary | 0058045: A user with a not Manual role can access, edit and create transactions in any organization | |||||||||||
| Description | A user with a not Manual role can access, edit and create transactions in any organization even if the organization access is limited to one store. | |||||||||||
| Steps To Reproduce | 1) Log as Orhi Store User 2) Go to Purchase Order Window 3) Create a new record 4) Mind that the organization combo displays the full list of organization when it should just display the organizations defined in the Org Access tab for his/her role 5) change the configuration for the role to Manual 6) Repeat the steps and mind that now the organizatiuon combo works properly | |||||||||||
| Proposed Solution | Workaround: it is possible to prevent access to organizations for automatic roles by creating those roles as disable (Active = false) in the Role > Org Access tab. | |||||||||||
| Tags | No tags attached. | |||||||||||
| Attached Files | ||||||||||||
Relationships [ Relation Graph ]
[ Dependency Graph ]
|
||||||||
|
||||||||
Issue History |
|||
| Date Modified | Username | Field | Change |
| 2025-02-21 08:35 | AugustoMauch | Type | defect => backport |
| 2025-02-21 08:35 | AugustoMauch | Target Version | pi => PR25Q1 |
| 2025-03-03 13:59 | AugustoMauch | Target Version | PR25Q1 => PR25Q1.1 |
| Copyright © 2000 - 2009 MantisBT Group |