c2c-oerpscenario team mailing list archive
-
c2c-oerpscenario team
-
Mailing list archive
-
Message #23450
[Bug 777850] [NEW] account_followup uses SQL query for getting data, cirmumventing security rules
Public bug reported:
this happens in v6 and trunk
Hi.
Currently account_followup uses SQL queries to get invoice and partners to sent followups to. This doesn't take security rules into account, which is wrong. And ORM way would do the right thing here.
For example a very bad effect of this is that in a multicompany
situation any user sees the open invoices of other companies, which
shouldn't be.
The interesting stuff happens here: http://bazaar.launchpad.net/~openerp
/openobject-
addons/trunk/view/head:/account_followup/wizard/account_followup_print.py
Thanks!
** Affects: openobject-addons
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of C2C
OERPScenario, which is subscribed to the OpenERP Project Group.
https://bugs.launchpad.net/bugs/777850
Title:
account_followup uses SQL query for getting data, cirmumventing
security rules
Status in OpenERP Modules (addons):
New
Bug description:
this happens in v6 and trunk
Hi.
Currently account_followup uses SQL queries to get invoice and partners to sent followups to. This doesn't take security rules into account, which is wrong. And ORM way would do the right thing here.
For example a very bad effect of this is that in a multicompany
situation any user sees the open invoices of other companies, which
shouldn't be.
The interesting stuff happens here:
http://bazaar.launchpad.net/~openerp/openobject-
addons/trunk/view/head:/account_followup/wizard/account_followup_print.py
Thanks!
Follow ups
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Leonardo Pistone - Agile BG - Domsense, 2011-05-27
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler (Win-Soft), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler (Win-Soft), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-26
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler (Win-Soft), 2011-05-25
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-17
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Leonardo Pistone - Domsense, 2011-05-16
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-12
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler, 2011-05-11
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-11
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-11
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Jay Vora (OpenERP), 2011-05-11
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler, 2011-05-10
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-10
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Thomas Winteler, 2011-05-10
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-10
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Launchpad Bug Tracker, 2011-05-10
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Jay Vora (OpenERP), 2011-05-09
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-09
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-09
-
Re: [Bug 777850] [NEW] account_followup uses SQL query for getting data, cirmumventing security rules
From: xrg, 2011-05-09
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Amit Dodiya (OpenERP), 2011-05-09
-
[Bug 777850] Re: account_followup uses SQL query for getting data, cirmumventing security rules
From: Leonardo Pistone - Domsense, 2011-05-06
-
[Bug 777850] [NEW] account_followup uses SQL query for getting data, cirmumventing security rules
From: Leonardo Pistone - Domsense, 2011-05-05
References