c2c-oerpscenario team mailing list archive
-
c2c-oerpscenario team
-
Mailing list archive
-
Message #25855
[Bug 722579] Re: [6.0] audit_trail settings should be readable by everyone, not just employee
Thank you for notification Nehal,
It has been fixed into stable by revision 4633
jvo@xxxxxxxxxxx-20110607071047-ubogvm2fndrhh1zd.
Thanks.
** Changed in: openobject-addons
Status: In Progress => Fix Released
** Changed in: openobject-addons
Milestone: None => 6.0.3
--
You received this bug notification because you are a member of C2C
OERPScenario, which is subscribed to the OpenERP Project Group.
https://bugs.launchpad.net/bugs/722579
Title:
[6.0] audit_trail settings should be readable by everyone, not just
employee
Status in OpenERP Modules (addons):
Fix Released
Bug description:
When audit_trail is installed, every request needs to go through an audit step, in which audit_trail tries to determine the auditing rules for the current action.
This should be available also for external users or portal users (that do not belong to the Employee group), as we want them to be audited too, and not see an error for each request.
Therefore security settings should allow everyone to access
audit_trail rules, or better, the rules should be read as "uid 1" to
avoid any problem with the access rights during the processing of each
request.
See also bug 719289 which discovered this issue while reporting an
issue with web client.
References