Attach filesAttach ScreenshotAdd voteVotersWatch issueWatchersLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Patch Available
    • Major
    • Resolution: Unresolved
    • None
    • None
    • product/catalog

    Description

      Currently, a user with only 'VIEW' permissions, as demonstrated in trunk demo with userId = auditor, accessing the Catalog Main Page, sees triggers (to requests) reserved for users with 'CREATE' or 'UPDATE' permissions.

      To see/test: https://demo-trunk.ofbiz.apache.org/catalog/control/main

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            jleroux Jacques Le Roux
            pierresmits Pierre Smits

            Dates

              Created:
              Updated:

              Slack

                Issue deployment