Bug #28628
closedCorporate User can able edit another corporate / any branch / department / designation / Employee details / Role Permission details
0%
Description
Create a corporate user for google corporate branch (google@mailinator.com / a) & login with corporate user, now only the login corporate branch is displayed and edit branch & the url contains branch id am changed the id at this another corporate branch displayed. Now we can able to change another corporate details. The issue founded in all forms Branch, Region , Regional unit, Department , Designation, Roles, Manage Employee.
Result required in this scenario if the user try to access another corporate show a validation you do not have permission to access another corporate / while do in this type of activity system need to logout the user and show alert message. "Suspicious Activity Detected! Please try aging later"
Files
Updated by Shamini K N 13 days ago
- Status changed from New to Closed
Duplicate — this issue already exists in QGO_CBT. No further action required.