Merge lp:~akretion-team/ocb-addons/70-addons-fix-payment-acls-bank into lp:ocb-addons
Status: | Rejected |
---|---|
Rejected by: | Holger Brunn (Therp) |
Proposed branch: | lp:~akretion-team/ocb-addons/70-addons-fix-payment-acls-bank |
Merge into: | lp:ocb-addons |
Diff against target: |
64 lines (+27/-0) 4 files modified
account/security/account_security.xml (+9/-0) account/security/ir.model.access.csv (+2/-0) account_payment/security/account_payment_security.xml (+14/-0) account_payment/security/ir.model.access.csv (+2/-0) |
To merge this branch: | bzr merge lp:~akretion-team/ocb-addons/70-addons-fix-payment-acls-bank |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Holger Brunn (Therp) | Disapprove | ||
Yannick Vaucher @ Camptocamp | Needs Fixing | ||
Raphaël Valyi - http://www.akretion.com | Needs Fixing | ||
Review via email: mp+208021@code.launchpad.net |
Description of the change
This MP aims at fixing the issue that I described long ago in this mail : https:/
In short : regular users are usually in the "Contact Creation" group because they need to create/modify partners. By default in OpenERP, it also grants them create/write permissions on bank accounts. If you use OpenERP to generate SEPA files and make payments, a regular user could modify the bank account of a supplier and put it's own bank account instead and receive the payments for the supplier on its own bank account ! As you can imagine, this is a problem :)
This merge proposal follows a discussion that took place in the banking-
Unmerged revisions
- 9949. By Alexis de Lattre
-
When the account module is installed, rights for the configuration of bank accounts are transfered from base.group_
partner_ manager to account. group_account_ manager
When the account_payment module is installed, full rights on bank accounts are transfered from base.group_partner_ manager to account_ payment. group_account_ payment because otherwize members of the Contact Creation group could easily divert a payment to a supplier.
Hello Alexis,
I would gladly approve the merge if:
1) it was linked to a bug report
2) there would be a MP for the official addons too as OCB policy requires
That looks like a horrible bureaucracy and at some point it is, but I think we should enforce OCB policy until eventually we re-discuss it and this bureaucracy today is in fact alleviating OCB maintainers work in the long run when eventually OpenERP SA will fix the bug in the official addons.