[ 
http://mifosforge.jira.com/browse/MIFOS-3143?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=69299#comment-69299
 ] 

Lukasz Chudy commented on MIFOS-3143:
-------------------------------------

Issues related to:

Can click into 'Create new Group'
Can click into 'Open new Loan Account'
Can click into 'Open new Savings Account'

still exist in Release 2.2
                
> System user without specific role able to perform ppi and survey actions.
> -------------------------------------------------------------------------
>
>                 Key: MIFOS-3143
>                 URL: http://mifosforge.jira.com/browse/MIFOS-3143
>             Project: mifos
>          Issue Type: Bug
>          Components: Configuration
>    Affects Versions: Release 1.5
>            Reporter: Jeff Brewster
>            Assignee: mifosdeveloperqueue
>             Fix For: Unscheduled
>
>
> Logging the remaining pending work from issue MIFOS-1951:
> If you create a new system user without assigning them a specific role, they 
> are able to perform
> any actions for which there aren't explicit permissions settings on the 'roles
> and permissions' page. So, a user
> without a role can also configure PPI, etc."
> The other examples I can find are:
> Configure PPI Settings
> Define new survey
> Define questions
> Could also create a client following the "Click here to continue if Group 
> membership is not required for your Client." path until the final submit for 
> approval.
> Can click into 'Create new Group'
> Can click into 'Open new Loan Account'
> Can click into 'Open new Savings Account'

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
http://mifosforge.jira.com/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a
definitive record of customers, application performance, security
threats, fraudulent activity and more. Splunk takes this data and makes
sense of it. Business sense. IT sense. Common sense.
http://p.sf.net/sfu/splunk-d2dcopy1
_______________________________________________
Mifos-issues mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mifos-issues

Reply via email to