[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Lucas Gass changed: What|Removed |Added CC||lu...@bywatersolutions.com Status|Pushed to stable|Pushed to oldstable Version(s)|24.05.00,23.11.04 |24.05.00,23.11.04,23.05.10 released in|| --- Comment #9 from Lucas Gass --- Backported to 23.05.x for upcoming 23.05.10. -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Fridolin Somers changed: What|Removed |Added Version(s)|24.05.00|24.05.00,23.11.04 released in|| Status|Pushed to master|Pushed to stable --- Comment #8 from Fridolin Somers --- Pushed to 23.11.x for 23.11.04 -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 --- Comment #7 from Katrin Fischer --- Pushed for 24.05! Well done everyone, thank you! -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Katrin Fischer changed: What|Removed |Added Version(s)||24.05.00 released in|| Status|Passed QA |Pushed to master -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Victor Grousset/tuxayo changed: What|Removed |Added Severity|major |normal --- Comment #6 from Victor Grousset/tuxayo --- (In reply to Fridolin Somers from comment #2) > I set major because it is a permission leak It's just displaying links which don't work because the server checks the permission before sending the page. And even if it did work, the post request for invoices and credit are also protected server side. (checked by loading the form, removing the permission and trying to make a manual invoice/credit) -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Victor Grousset/tuxayo changed: What|Removed |Added QA Contact|testo...@bugs.koha-communit |vic...@tuxayo.net |y.org | CC||vic...@tuxayo.net Status|Signed Off |Passed QA --- Comment #5 from Victor Grousset/tuxayo --- Works, makes sense, QA script happy, code looks good, passing QA :) -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Victor Grousset/tuxayo changed: What|Removed |Added Attachment #162252|0 |1 is obsolete|| --- Comment #4 from Victor Grousset/tuxayo --- Created attachment 162707 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=162707=edit Bug 36076: paycollect.tt add permission checks for manual credit and invoice In members/pay.tt one can see permission checks for manual credit and invoice : CAN_user_updatecharges_manual_invoice CAN_user_updatecharges_manual_credit This is missing from members/paycollect.tt. HTML is also missing classes manualcredit and manualinvoice. Test plan : 1) Create a user with permissions to manage accounting (remaining_permissions under updatecharges) but without manual_invoice and manual_credit 2) Go to a patron account with an invoice 3) Click on "Make a payment", you dont see tabs manual credit/invoice 4) Click on "Pay" in "Actions" column => Without patch you see tabs manual credit/invoice => With patch you do not see them Signed-off-by: David Nind Signed-off-by: Victor Grousset/tuxayo -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 David Nind changed: What|Removed |Added Attachment #162088|0 |1 is obsolete|| --- Comment #3 from David Nind --- Created attachment 162252 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=162252=edit Bug 36076: paycollect.tt add permission checks for manual credit and invoice In members/pay.tt one can see permission checks for manual credit and invoice : CAN_user_updatecharges_manual_invoice CAN_user_updatecharges_manual_credit This is missing from members/paycollect.tt. HTML is also missing classes manualcredit and manualinvoice. Test plan : 1) Create a user with permissions to manage accounting but without manual_invoice and manual_credit 2) Go to a patron account with an invoice 3) Click on "Make a payment", you dont see tabs manual credit/invoice 4) Click on "Pay" in "Actions" column => Without patch you see tabs manual credit/invoice => With patch you do not see them Signed-off-by: David Nind -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 David Nind changed: What|Removed |Added Status|Needs Signoff |Signed Off -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Fridolin Somers changed: What|Removed |Added Severity|normal |major --- Comment #2 from Fridolin Somers --- I set major because it is a permission leak -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 --- Comment #1 from Fridolin Somers --- Created attachment 162088 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=162088=edit Bug 36076: paycollect.tt add permission checks for manual credit and invoice In members/pay.tt one can see permission checks for manual credit and invoice : CAN_user_updatecharges_manual_invoice CAN_user_updatecharges_manual_credit This is missing from members/paycollect.tt. HTML is also missing classes manualcredit and manualinvoice. Test plan : 1) Create a user with permissions to manage accounting but without manual_invoice and manual_credit 2) Go to a patron account with an invoice 3) Click on "Make a payment", you dont see tabs manual credit/invoice 4) Click on "Pay" in "Actions" column => Without patch you see tabs manual credit/invoice => With patch you do not see them -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Fridolin Somers changed: What|Removed |Added Patch complexity|--- |Trivial patch Status|ASSIGNED|Needs Signoff -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
[Koha-bugs] [Bug 36076] paycollect.tt is missing permission checks for manual credit and invoice
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36076 Fridolin Somers changed: What|Removed |Added Assignee|koha-b...@lists.koha-commun |fridolin.som...@biblibre.co |ity.org |m Status|NEW |ASSIGNED -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes. ___ Koha-bugs mailing list Koha-bugs@lists.koha-community.org https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/