Pierre Smits created OFBIZ-12451:
------------------------------------

             Summary: VIEW permissions PaymentsDepositWithdraw
                 Key: OFBIZ-12451
                 URL: https://issues.apache.org/jira/browse/OFBIZ-12451
             Project: OFBiz
          Issue Type: Improvement
          Components: accounting
    Affects Versions: Trunk
            Reporter: Pierre Smits
            Assignee: Pierre Smits


Currently, a user with only 'VIEW' permissions, as demonstrated in trunk demo 
with userId = auditor, accessing the Financial Account 'Deposit/Withdraw screen 
 sees editable fields and/or triggers (to requests) reserved for users with 
'CREATE' or 'UPDATE' permissions.

See (test with):
 * 
[https://demo-trunk.ofbiz.apache.org/accounting/control/EditFinAccount?finAccountId=ABN_CHECKING]
 * 
https://demo-trunk.ofbiz.apache.org/accounting/control/FindPaymentsForDepositOrWithdraw



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to