#865 Users require *_edit roles for almost everything

1.4
closed-fixed
Chris Travers
None
5
2014-01-11
2013-06-16
Erik Huelsmann
No

From IRC, just now:

[18:59] <freelock_> Hmm, with an account I have pretty restricted, I'm getting access denied all over the place --
[18:59] <freelock_> looks like mainly to account_heading, which requires lsmb_<db>account_edit for select
[19:01] <freelock_> I'm also not finding any screen in 1.4 to edit permissions -- having to add roles directly in psql
[19:01] <freelock_> confirmed that lsmb_<db>
account_edit is necessary for most search screens
[19:07] <freelock_> budget_* tables don't have any select permissions
[19:11] <freelock_> trial balance doesn't work -- perl error
[19:16] <freelock_> balance sheet has permissions errors -- was able to run after adding lsmb_<dbname>__account_edit to the view account_heading_tree
[19:18] <freelock_> sales order report search shows only customer number, not customer name
[19:19] <freelock_> sales order report ignores customer name in search

Discussion

  • Chris Travers
    Chris Travers
    2014-01-10

    I would like to split this into two tickets:

    1. Overly restrictive use of account_edit
    2. Needing _edit for things like financial transactions.

    The first would be 1.4, the second 1.5.

     
    Last edit: Chris Travers 2014-01-10
  • Chris Travers
    Chris Travers
    2014-01-10

    • assigned_to: Chris Travers
     
  • Chris Travers
    Chris Travers
    2014-01-11

    6441

     
  • Chris Travers
    Chris Travers
    2014-01-11

    • status: open --> closed-fixed
     
  • Chris Travers
    Chris Travers
    2014-01-11

    As a note, if this is not resolved here, we need to have more detail in terms of which tables are at issue.