Peter Santa created FINERACT-1980:
-------------------------------------
Summary: 4-eye checker user can approve their own make command
Key: FINERACT-1980
URL: https://issues.apache.org/jira/browse/FINERACT-1980
Project: Apache Fineract
Issue Type: Bug
Components: Security
Affects Versions: 1.9.0
Reporter: Peter Santa
Fix For: 1.9.0
h1. Steps to reproduce
* Enable maker-checker functionality and create a role with permission to make
and check journal entries
* Create a journal entry
* Send approval for create journal entry command (POST
/makercheckers/\{{original make journal entry command ID}}?command=approve)
h1. Expected results
Check request for own command cannot be executed
h1. Real results
Check request for own command can be executed
--
This message was sent by Atlassian Jira
(v8.20.10#820010)