Peter Santa created FINERACT-1980:
-------------------------------------

             Summary: 4-eye checker user can approve their own make command
                 Key: FINERACT-1980
                 URL: https://issues.apache.org/jira/browse/FINERACT-1980
             Project: Apache Fineract
          Issue Type: Bug
          Components: Security
    Affects Versions: 1.9.0
            Reporter: Peter Santa
             Fix For: 1.9.0


h1. Steps to reproduce
 * Enable maker-checker functionality and create a role with permission to make 
and check journal entries
 * Create a journal entry
 * Send approval for create journal entry command (POST 
/makercheckers/\{{original make journal entry command ID}}?command=approve)

h1. Expected results

Check request for own command cannot be executed
h1. Real results

Check request for own command can be executed



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to