Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-5824

Error in communication screen while perfom sorting

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: Release Branch 13.07, Trunk
    • Fix Version/s: 14.12.01, 12.04.06, 13.07.02
    • Component/s: None
    • Labels:
      None

      Description

      In partymgr contrller.xml, we have view request named "ViewCommunicationEvent", and this request call an service event, due to this when we try to perform sorting on Child Communication Events, Customer Request List or any other screen over Communication screen then it will thorw following exception:

      org.ofbiz.webapp.event.EventHandlerException: Found URL parameter [communicationEventId] passed to secure (https) request-map with uri [ViewCommunicationEvent] with an event that calls service [setCommEventRoleToRead]; this is not allowed for security reasons! The data should be encrypted by making it part of the request body (a form field) instead of the request URL. Moreover it would be kind if you could create a Jira sub-task of https://issues.apache.org/jira/browse/OFBIZ-2330 (check before if a sub-task for this error does not exist). If you are not sure how to create a Jira issue please have a look before at http://cwiki.apache.org/confluence/x/JIB2 Thank you in advance for your help.
       

      Also due to this service event call on view request entry we can't open the communication events in new tab. Ideally this service should be call in screen context instead view request.

        Activity

        Hide
        deepak.dixit Deepak Dixit added a comment -

        Here is the patch for the issue.
        Removed service call from request and moved service call to screen, Also removed the duplicate viewCommunicationEvent request.

        Show
        deepak.dixit Deepak Dixit added a comment - Here is the patch for the issue. Removed service call from request and moved service call to screen, Also removed the duplicate viewCommunicationEvent request.
        Hide
        toashishvijay Ashish Vijaywargiya added a comment -

        Thanks Deepak for the contribution. Your changes are committed to trunk at r1632745 and to Release Branch 13.07 at r1632746.

        Show
        toashishvijay Ashish Vijaywargiya added a comment - Thanks Deepak for the contribution. Your changes are committed to trunk at r1632745 and to Release Branch 13.07 at r1632746.
        Hide
        jacques.le.roux Jacques Le Roux added a comment -

        Backported in R12.04 at r1632998

        Show
        jacques.le.roux Jacques Le Roux added a comment - Backported in R12.04 at r1632998

          People

          • Assignee:
            toashishvijay Ashish Vijaywargiya
            Reporter:
            deepak.dixit Deepak Dixit
          • Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development