View Issue Details

IDProjectCategoryView StatusLast Update
0005927OXID ERP InterfaceOXID ERP Interface - subpublic2024-12-11 11:55
Reportermichael_keiluweit Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionno change required 
Product Version2.13.0 
Summary0005927: oxarticle and oxcategory Objects are deleteable without having the permission by Rights and Roles when using ERP / CSV.
DescriptionWhen the rights and roles for an article (or a category) object are set to only readable or not accessable and it is not explicit set in the submenu "objects", too (Please have a look at attached pictures 1 and 2), then the object is deletable.
Additional Informationthis works also for all non article/category objects, but for those the complete rights and roles aren't working. See 0005926
TagsCSV, EE, ERP, Rights & Roles, SOAP
Attached Files
1.PNG (12,332 bytes)   
1.PNG (12,332 bytes)   
2.PNG (15,984 bytes)   
2.PNG (15,984 bytes)   
3.PNG (27,360 bytes)   
3.PNG (27,360 bytes)   

Relationships

related to 0005926 confirmedSvenBrunk Rights and Roles doesn't work with ERP / CSV module... 

Activities

SvenBrunk

2024-12-11 11:55

manager   ~0017768

This works exactly as designed. The rights and roles panel only controls what actions are available to you in the admin area. Only the object rights control what you are allowed to do and this is also only defined for oxarticles and oxcategories. From your screenshot you ARE allowed to delete both from oxarticles and from oxcategories.