Code review comment for lp:~cubicerp/openobject-server/7.0-fix-bug-1073087-multicompany-access-denied

Revision history for this message
Cubic ERP (cubicerp) wrote :

Dear Oliver, please explain me about your test realized to you said:

"... what it does will break the access right system of OpenERP. It would allow users to bypass all access rules and perform operations on records on unauthorized records as long as they also touch one record that they can access - this is a dangerous security hole..."

I need review your tests because on my tests it isn't a security hole.

best regards.

« Back to merge proposal