[jira] [Commented] (OFBIZ-2729) special security should be required for setting passwords

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Commented] (OFBIZ-2729) special security should be required for setting passwords

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-2729?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13258034#comment-13258034 ]

Jacques Le Roux commented on OFBIZ-2729:
----------------------------------------

Ping
               

>  special security should be required for setting passwords
> ----------------------------------------------------------
>
>                 Key: OFBIZ-2729
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-2729
>             Project: OFBiz
>          Issue Type: Sub-task
>          Components: framework
>    Affects Versions: Release Branch 4.0, Release Branch 09.04, SVN trunk
>            Reporter: Si Chen
>
>  This issue was first brought up here: https://sourceforge.net/forum/message.php?msg_id=7496877
>  Basically, any user with PARTYMGR_CREATE/UPDATE  permissions can set the password of another user. This creates opportunity for  Malfeasance. For example, a customer service rep  could set the password of the admin user.
> A simple solution would be to create a new security permission PARTYMGR_PASSWD  and require that permission  for setting or changing password of a different user, instead of using PARTYMGR_UPDATE.  PARTYMGR_PASSWD  could then be associated with  the administrative user.
>  An alternative is to use the SECURITY_UPDATE  permission instead of PARTYMGR_UPDATE  or  a new PARTYMGR_PASSWD  permission.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira