[jira] [Commented] (OFBIZ-4130) Tenant super user (tenant admin) can view all database details of all tenants

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Commented] (OFBIZ-4130) Tenant super user (tenant admin) can view all database details of all tenants

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-4130?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13949183#comment-13949183 ]

Jacopo Cappellato commented on OFBIZ-4130:
------------------------------------------

I had finally time to dig into this problem.
There is indeed an issue (as reported by Pierre) in the code written by Hans; however (as commented by Hans) the solution/fix proposed by Pierre is wrong.
Please find the attached patch that *should* fix the issue in the proper way.
From what I understand you both are selling services based on the multi-tenant features of OFBiz: so please test it and let me know if it can be committed to the trunk (and release branches).
I hope this solution will set an end to this never-ending story.

> Tenant super user (tenant admin) can view all database details of all tenants
> -----------------------------------------------------------------------------
>
>                 Key: OFBIZ-4130
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-4130
>             Project: OFBiz
>          Issue Type: Bug
>          Components: framework
>    Affects Versions: Release Branch 10.04, Release Branch 11.04, SVN trunk, Release Branch 12.04, Release Branch 13.07
>            Reporter: Pierre Smits
>            Priority: Critical
>             Fix For: Release Branch 10.04, Release Branch 11.04, SVN trunk, Release 11.04.01, Release Branch 12.04, Release Branch 13.07
>
>         Attachments: OFBIZ-4130-MultiTenant-visibilty.patch
>
>
> When a new tenant is created and the super user of the tenant (the tenant-admin) logs in to WebTools and views the tables Tenant and TenantDataSource he/she can see all details of the tenant databases, incl TenantName, userID and password of the tenant databases.



--
This message was sent by Atlassian JIRA
(v6.2#6252)