[ 
https://issues.apache.org/jira/browse/OFBIZ-12490?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Pierre Smits closed OFBIZ-12490.
--------------------------------
    Fix Version/s: Upcoming Branch
       Resolution: Implemented

Thanks to Jacques to get this into the codebase.

> Category Products - VIEW permissions
> ------------------------------------
>
>                 Key: OFBIZ-12490
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-12490
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: product/catalog
>    Affects Versions: Upcoming Branch
>            Reporter: Pierre Smits
>            Assignee: Pierre Smits
>            Priority: Major
>              Labels: category, permissions, product, trust, usability, ux
>             Fix For: Upcoming Branch
>
>
> Currently, a user with only 'VIEW' permissions, as demonstrated in trunk demo 
> with userId = auditor, accessing the category products screen, sees editable 
> fields and/or triggers (to requests) reserved for users with 'CREATE' or 
> 'UPDATE' permissions.
> See (test with): 
> https://localhost:8443/catalog/control/EditCategoryProducts?productCategoryId=100



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to