Actions
Bug #28628
closedCorporate User can able edit another corporate / any branch / department / designation / Employee details / Role Permission details
Status:
Closed
Priority:
Immediate
Assignee:
-
Target version:
Corporate Booking Tool Module - 1st Version - V1.0
Start date:
10/17/2025
Due date:
% Done:
0%
Estimated time:
remarks:
DB Changes:
Keys & Permissions:
Areas Affected:
Files Changed:
Description
Create a corporate user for google corporate branch (google@mailinator.com / a) & login with corporate user, now only the login corporate branch is displayed and edit branch & the url contains branch id am changed the id at this another corporate branch displayed. Now we can able to change another corporate details. The issue founded in all forms Branch, Region , Regional unit, Department , Designation, Roles, Manage Employee.
Result required in this scenario if the user try to access another corporate show a validation you do not have permission to access another corporate / while do in this type of activity system need to logout the user and show alert message. "Suspicious Activity Detected! Please try aging later"
Files
Actions