There is a section of code that is commented out in
ModelPermission.evalRoleMember().  The comment indicates that it is a
security risk.
Could someone tell what risk it presents.

As this code is masked out, role-based security is effectively disabled.  In
addition, the code is looking for from/thru date which are not a part of the
PartyRole entity.

Could someone provide some insight.

Thanks,
Wai


-- 
View this message in context: 
http://ofbiz.135035.n4.nabble.com/Role-based-security-is-disabled-tp2319089p2319089.html
Sent from the OFBiz - Dev mailing list archive at Nabble.com.

Reply via email to