[
https://issues.apache.org/jira/browse/OFBIZ-12391?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17452357#comment-17452357
]
Pierre Smits edited comment on OFBIZ-12391 at 12/2/21, 11:49 AM:
-----------------------------------------------------------------
[~mbrohl],
Your initial argument(s) did't hold merit, and the new ones don't either. The
paradigm you say it breaks is not there (unless you refer to the paradigm of
inconsistency). Initially (and still), the code comes with functionality of
fields being added to tables, without explicit definition in entities (the
transaction fields). These fields are the same, falling under that paradigm:
applicable to all entities.
was (Author: pfm.smits):
[~mbrohl],
Your initial argument(s) did't hold merit, and the new one don't either. The
paradigm you say it breaks is not there (unless you refer to the paradigm of
inconsistency). Initially (and still), the code comes with functionality of
fields being added to tables, without explicit definition in entities (the
transaction fields). These fields are the same, falling under that paradigm:
applicable to all entities.
> Trustworthy OFBiz - audit capabilities
> --------------------------------------
>
> Key: OFBIZ-12391
> URL: https://issues.apache.org/jira/browse/OFBIZ-12391
> Project: OFBiz
> Issue Type: Improvement
> Components: ALL COMPONENTS, framework/entity
> Affects Versions: Trunk
> Reporter: Pierre Smits
> Assignee: Pierre Smits
> Priority: Major
> Labels: audit, entity, investigation, mvp, trust, usability
>
> When potential adopters want to use OFBiz as their primary solution for
> business critical ERP (and related) processes, they (or at least their
> auditors) want to be sure that they can see:
> # who created the record in the underlying rdbms,
> # when that record was created,
> # who was the last one to modify the record
> # when the modification happened.
> Currently out of the 800+ entities defined in the various entity model files,
> only a fraction of the entities have fields defined for
> * createdDate (23)
> * createdByUserLogin (30)
> * lastModifiedDate (24)
> * lastModifiedByUserLogin (29)
> which means that for crucial entities (for a business) in OFBiz entities
> records can be created and changed (for nefarious reasons) without auditors
> and other investigators being able to state anything regarding the above 4
> points.
> Currently there are over 600 entity-auto services invoking 'create', and
> approximately the same amount of services that invoke 'update', that could
> automatically set the fields listed above. However it is not done, because
> these have not been defined.
>
>
--
This message was sent by Atlassian Jira
(v8.20.1#820001)