Skip to content

Comments

Improved: VIEW permissions - BillingAccount roles (OFBIZ-12487)#440

Merged
JacquesLeRoux merged 1 commit intoapache:trunkfrom
PierreSmits:12487-VIEW-BillingAccount-Roles
Jan 20, 2022
Merged

Improved: VIEW permissions - BillingAccount roles (OFBIZ-12487)#440
JacquesLeRoux merged 1 commit intoapache:trunkfrom
PierreSmits:12487-VIEW-BillingAccount-Roles

Conversation

@PierreSmits
Copy link
Member

Currently, a user with only 'VIEW' permissions, as demonstrated in trunk demo with userId = auditor, accessing the billing account roles screen, sees editable fields and/or triggers (to requests) reserved for users with 'CREATE' or 'UPDATE' permissions.
See (test with): https://localhost:8443/accounting/control/EditBillingAccountRoles?billingAccountId=9010

Modified:
BillingAccountScreens.xml, re EditBillingAccountRoles:

  • added permission rules for CREATE/UPDATE
  • restructured section and widget/fail-widget elements, additional cleanup
    BillingAccountForms.xml
  • added grid BillingAccountRoles (based on ListBillingAccountRoles)
  • additional cleanup/label harmonisation

Currently, a user with only 'VIEW' permissions, as demonstrated in trunk demo with userId = auditor, accessing the billing account roles screen, sees editable fields and/or triggers (to requests) reserved for users with 'CREATE' or 'UPDATE' permissions.
See (test with): https://localhost:8443/accounting/control/EditBillingAccountRoles?billingAccountId=9010

Modified:
BillingAccountScreens.xml, re EditBillingAccountRoles:
- added permission rules for CREATE/UPDATE
- restructured section and widget/fail-widget elements, additional cleanup
BillingAccountForms.xml
- added grid BillingAccountRoles (based on ListBillingAccountRoles)
- additional cleanup/label harmonisation
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@JacquesLeRoux JacquesLeRoux merged commit b53d56f into apache:trunk Jan 20, 2022
@PierreSmits PierreSmits deleted the 12487-VIEW-BillingAccount-Roles branch January 20, 2022 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants