Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0009981
TypeCategorySeverityReproducibilityDate SubmittedLast Update
backport[Openbravo ERP] C. Securitymajoralways2009-07-21 12:092009-07-22 12:28
ReporternetworkbView Statuspublic 
Assigned Toalostale 
PriorityimmediateResolutionfixedFixed in Version2.40MP8
StatusclosedFix in branch2.40Fixed in SCM revision01efdf924dc1
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product Version2.40MP7SCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0009981: Linked items show elements in windows where the role has no permission

DescriptionFor example, a role is created only to access to Business Partner window.
A user access the application with this role.
Go to Business Partner, and select an existing one.
Press Linked items, and shows information, for example, about Manual settlement.
This is not correct. It must only show information about those elements that role can navigate.
Steps To Reproduce1)Create a Business partner.
Select as Employee.
Go to Manual Settlement. Create a new one.
In Create payment tab, select the partner in 1). As amount, 1000.
Go to Balance payment, select one GL/Item, and enter 1000 as debit amount.
Process it.
Back to Business partner window. Press linked items. The manual settlement is shown (it is supposed that role can access to Manual Settlement)
-------------------
Create a new role, just to access Business partner window.
Create a new user for this role.
Enter as this user.
Go to Business Partner window. Find the partner created in 1)
Press Linked items. Pop-up shows a link to Manual Settlement, including its amount. This must not happen
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
related to backport 00099502.50MP4 closedsathiyan The employees have acces to their payroll 
blocks defect 0009979 closedalostale Linked items show elements in windows where the role has no permission 

-  Notes
(0018504)
hgbot (developer)
2009-07-21 17:42

Repository: erp/stable/2.40
Changeset: 01efdf924dc1b13f52370daf42f465d6d57fa1ca
Author: Asier Lostalé <asier.lostale <at> openbravo.com>
Date: Tue Jul 21 17:42:10 2009 +0200
URL: http://code.openbravo.com/erp/stable/2.40/rev/01efdf924dc1b13f52370daf42f465d6d57fa1ca [^]

fixed bug 0009981: Linked items show elements in windows where the role has no permission

---
M src/org/openbravo/erpCommon/utility/UsedByLink.java
M src/org/openbravo/erpCommon/utility/UsedByLink_data.xsql
---
(0018548)
sureshbabu (reporter)
2009-07-22 12:28

Tested working fine

- Issue History
Date Modified Username Field Change
2009-07-21 12:41 rafaroda Type defect => backport
2009-07-21 12:41 rafaroda fix_in_branch => 2.40
2009-07-21 13:40 rafaroda Relationship added related to 0009950
2009-07-21 17:42 hgbot Checkin
2009-07-21 17:42 hgbot Note Added: 0018504
2009-07-21 17:42 hgbot Status scheduled => resolved
2009-07-21 17:42 hgbot Resolution open => fixed
2009-07-21 17:42 hgbot Fixed in SCM revision => http://code.openbravo.com/erp/stable/2.40/rev/01efdf924dc1b13f52370daf42f465d6d57fa1ca [^]
2009-07-22 12:28 sureshbabu Status resolved => closed
2009-07-22 12:28 sureshbabu Note Added: 0018548
2009-07-22 12:28 sureshbabu Fixed in Version => 2.40MP8


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker