Sidebar displays customisation links for all users

Bug #652179 reported by James Jesudason
This bug report is a duplicate of:  Bug #702158: Right Toolbar: Customize. Edit Remove
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Odoo Web Client
Fix Released
Wishlist
OpenERP R&D Web Team

Bug Description

The web client has some extra options in the sidebar to allow views and objects to be customised e.g. Manage View, Customise Objects. These do not seem to be controlled by security groups, so they are being displayed for all users. These should only be displayed for Administrators.

bzr revno: 3369

Navrang Oza (noz-tiny)
Changed in openobject-client-web:
importance: Undecided → Low
importance: Low → Wishlist
Revision history for this message
Ferdinand (office-chricar) wrote :

generally I would wish that the right menu is controlled the same way as the normal menu - just show what a user is allowed to do and should als be controllable by menu structure

Revision history for this message
James Jesudason (jamesj) wrote :

To me this is a security flaw in the system. A malicious user could customise a view to display fields that should not be shown or even to remove existing fields.

Changed in openobject-client-web:
status: New → Confirmed
importance: Wishlist → Medium
assignee: nobody → OpenERP SA's Web Client R&D (openerp-dev-web)
Navrang Oza (noz-tiny)
Changed in openobject-client-web:
importance: Medium → Wishlist
Revision history for this message
Navrang Oza (noz-tiny) wrote :

Hello James Jesudason,

Customize section and Translation will available only for Administrator now.

Fixed in web-trunk.
4320 <email address hidden>

Please update your branch.
Thanks.

Changed in openobject-client-web:
status: Confirmed → Fix Released
milestone: none → 6.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.