web client allows add of item with only UPDATE_COPY permission

Bug #1763811 reported by Robert J Jackson
46
This bug affects 9 people
Affects Status Importance Assigned to Milestone
Evergreen
Confirmed
Undecided
Unassigned

Bug Description

web client 3.0.5

using our definition of a circ1 account did the following:

1. Searched by ISBN in the Keyword search in the Catalog

2. Clicked on the item record

3. Selected Add Volumes

4. Typed in the call no. and barcode

5. Changed the Evergreen Audience ( to allow me to save the volume/copy)

6. Clicked Save & Exit.

The window closed as per usual and the item was added to the record.

When reviewing the transaction in the osrfsys log file the only permission checked was UPDATE_COPY

bjackson@mig:/var/log/evergreen/2018/04/13$ grep 152217637125921193 osrfsys.14.log|grep perm=
2018-04-13 14:28:56 mig open-ils.cat: [INFO:13433:CStoreEditor.pm:139:152217637125921193] editor[1|1099308] checking perms user=1099308, org=61, perm=UPDATE_COPY

Tags: cataloging
Andrea Neiman (aneiman)
tags: added: cataloging
tags: removed: webstaffclient
Revision history for this message
Elaine Hardy (ehardy) wrote :

Still an issue with 3.10 and 3.8

Changed in evergreen:
status: New → Confirmed
Revision history for this message
Britta Dorsey (bdorsey-isl) wrote :

Evergreen 3.9.1

Circ1 account was able to create an item on our practice server.

Revision history for this message
Andrea Neiman (aneiman) wrote :

Evergreen Indiana has contacted with Equinox to produce a fix for this bug.

Changed in evergreen:
assignee: nobody → Andrea Neiman (aneiman)
Revision history for this message
Andrea Neiman (aneiman) wrote :

The work we're doing will also address bug 1853062

Revision history for this message
Jason Etheridge (phasefx) wrote :

I've created an omnibus bug for this and other improvements at
https://bugs.launchpad.net/evergreen/+bug/2061136

Andrea Neiman (aneiman)
Changed in evergreen:
assignee: Andrea Neiman (aneiman) → nobody
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.