Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0058085
TypeCategorySeverityReproducibilityDate SubmittedLast Update
backport[Openbravo ERP] A. Platformmajorhave not tried2024-12-18 10:462025-02-26 17:57
ReporteramartinezView Statuspublic 
Assigned ToTriage Platform Base 
PrioritynormalResolutionfixedFixed in VersionPR25Q1
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget VersionPR25Q1
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Statusapproved
Review Assigned To
OBNetwork customerGold
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0058085: broken layout in save view - Some flows are still broken

DescriptionThis issue is a continuation of https://issues.openbravo.com/view.php?id=56753 [^]

Improper names (ie. with some special characters) for standard windows saved views, can break the layout when they are displayed.

- The problem is still being reproduced on the Delete View flow
Steps To ReproduceIn a registered instance:

1. Log in backoffice
2. Open any window
3. In the toolbar click on Save View
4. Enter a name with invalid format and save
5. In that window click on Save View again to display the name of the view saved in the previous step
6. In Save View, select Save View
7. In Save View select Delete View
  ERROR: Broken layout
Proposed SolutionView names should be properly treated when they are going to be displayed.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
blocks defect 0057477 closedTriage Platform Base broken layout in save view - Some flows are still broken 

-  Notes
(0176175)
hgbot (developer)
2025-02-26 17:57

Merge Request created: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/merge_requests/1558 [^]
(0176176)
hgbot (developer)
2025-02-26 17:57

Merge request merged: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/merge_requests/1558 [^]
(0176177)
hgbot (developer)
2025-02-26 17:57

Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo [^]
Changeset: 402a9646aefa6578f91969f389cd09fc2061931c
Author: ALEJANDRO MARTINEZ <a.martinez@orisha.com>
Date: 26-02-2025 17:56:27
URL: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/commit/402a9646aefa6578f91969f389cd09fc2061931c [^]

Fixes ISSUE-58085: Complete character escaping in delete view to cover all XSS injection points

---
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/main/ob-standard-window.js
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/personalization/ob-manage-views-popups.js
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/personalization/ob-manage-views-toolbar.js
---

- Issue History
Date Modified Username Field Change
2025-02-26 17:51 AugustoMauch Type defect => backport
2025-02-26 17:51 AugustoMauch Target Version => PR25Q1
2025-02-26 17:57 hgbot Note Added: 0176175
2025-02-26 17:57 hgbot Note Added: 0176176
2025-02-26 17:57 hgbot Resolution open => fixed
2025-02-26 17:57 hgbot Status scheduled => closed
2025-02-26 17:57 hgbot Fixed in Version => PR25Q1
2025-02-26 17:57 hgbot Note Added: 0176177


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker