← Back to team overview

openerp-india team mailing list archive

[Bug 1130712] Re: Anonymous user can DELETE filters when debug GET parameter is activated

 

** Attachment added: "filter.ogv"
   https://bugs.launchpad.net/openobject-addons/+bug/1130712/+attachment/3546065/+files/filter.ogv

** Project changed: openobject-addons => openobject-server

** Changed in: openobject-server
   Importance: Undecided => Medium

** Changed in: openobject-server
       Status: New => Confirmed

** Changed in: openobject-server
     Assignee: (unassigned) => OpenERP's Framework R&D (openerp-dev-framework)

-- 
You received this bug notification because you are a member of OpenERP
Indian Team, which is subscribed to OpenERP Server.
https://bugs.launchpad.net/bugs/1130712

Title:
  Anonymous user can DELETE filters when debug GET parameter is
  activated

Status in OpenERP Server:
  Confirmed

Bug description:
  When the public portal functionality is activated, the anonymous user
  can CREATE/DELETE defined filters from the system.

  How to reproduce:

  1. Activate the public portal functionality
  2. specify the debug GET parameter on the url
  3. in the debug menu, click 'Manage filters'
  4. clear the automatically applied filters (all filters are shown)
  5. Select any of the filters and delete it.

  Expected behaviour: No display of filters at all.

To manage notifications about this bug go to:
https://bugs.launchpad.net/openobject-server/+bug/1130712/+subscriptions