Commit Graph

104 Commits

Author SHA1 Message Date
Paula Quispe
36c8a38fea HOR-4404 2018-03-06 13:46:32 -04:00
Paula Quispe
b59026fe51 Merged in bugfix/HOR-3612 (pull request #6190)
HOR-3612

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-12-01 13:27:44 +00:00
Paula Quispe
c6958575b7 HOR-3612 2017-11-22 09:49:41 -04:00
Paula Quispe
f5355c07bd Merged in release/3.2.2 (pull request #6198)
release/3.2.2

Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-11-21 20:34:09 +00:00
Paula Quispe
a52462b4ec HOR-4102 2017-11-21 13:57:53 -04:00
Paula Quispe
32bfcd2121 release/3.2.2 2017-11-03 09:53:47 -04:00
Marco Antonio Nina Mena
33a6e236b9 HOR-4017 CLONE 3.2.2 - Unauthenticated download of any file from server with "processes/processes_GetFile" page + Path Traversal
- Add validation path only PATH_DATA_MAILTEMPLATES or PATH_DATA_PUBLIC
2017-10-30 08:31:21 -04:00
Paula Quispe
81c90278bd release/3.2.2 to develop conflicts 2017-10-23 11:37:41 -04:00
Paula Quispe
5327ecdfd5 HOR-3926 2017-10-20 12:00:11 -04:00
davidcallizaya
2a81bba175 HOR-3956
Fix CR
2017-10-20 12:00:11 -04:00
davidcallizaya
7d99f1e69e HOR-3956
+ Enable access to guest user to use the PM_CASES.
+ Add PM_DASHBOARD permission to KPIs.
+ Add internal permission alias:
RBAC->userCanAccess()
     * Verify if the user has a right over the permission. Ex.
     *      $rbac->userCanAccess("PM_CASES");
     *
     * Alias of permissions:
     *      PM_CASES has alias: PM_GUES_CASE
     * This means that a role with PM_GUES_CASE could access like one with PM_CASES
     * unless the permission is required as strict, like this:
     *      $rbac->userCanAccess("PM_CASES/strict");
2017-10-20 12:00:10 -04:00
davidcallizaya
ed32b004f1 HOR-3946
Fix guest username.
2017-10-20 12:00:10 -04:00
Roly Rudy Gutierrez Pinto
69f26c6eee HOR-3926 2017-10-20 12:00:09 -04:00
Roly Rudy Gutierrez Pinto
77b828d67a HOR-3926 2017-10-20 12:00:09 -04:00
Roly Rudy Gutierrez Pinto
fb4a8a4bc3 HOR-3926 2017-10-20 12:00:08 -04:00
Roly Rudy Gutierrez Pinto
465264d57c HOR-3926 2017-10-20 12:00:08 -04:00
davidcallizaya
2509ba1612 HOR-3925
Fix CR observations
2017-10-20 12:00:08 -04:00
davidcallizaya
128e42e71e HOR-3925
Create a user guest by default.
2017-10-20 12:00:08 -04:00
Marco Antonio Nina Mena
37b2a39c9f Merged in bugfix/HOR-3858 (pull request #6106)
HOR-3858

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-10-19 22:01:43 +00:00
Paula Quispe
adc0c23acf HOR-3980 2017-10-18 16:02:20 -04:00
Marco Antonio Nina Mena
99700467b8 HOR-3858 Unauthenticated download of any file from server with "processes/processes_GetFile" page + Path Traversal
- Add validation path only PATH_DATA_MAILTEMPLATES or PATH_DATA_PUBLIC
- exists process uid
2017-10-10 16:18:22 -04:00
Roly
ac313f342c Merged in bugfix/HOR-3221 (pull request #6052)
HOR-3221

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-09-25 20:36:16 +00:00
Roly Rudy Gutierrez Pinto
59fc56265a HOR-3221 improvement 2017-09-19 11:19:45 -04:00
Paula Quispe
32927ea06b HOR-3866 2017-09-12 12:13:05 -04:00
David Callizaya
ab9c67fb47 HOR-3670
Fix class name PmLicenseManager.
2017-08-11 17:42:02 -04:00
Marco A. Nina Mena
2820ba7de3 fix code review
o
2017-08-10 16:30:32 -04:00
Marco A. Nina Mena
4683f5b59d Add functionality in rbac for enable or disable compatibility with soap login 2017-08-10 14:38:48 -04:00
Paula Quispe
deb4999537 HOR-2949 2017-08-09 12:03:25 -04:00
Ronald Quenta
23844188b3 Merge remote-tracking branch 'origin/feature/HOR-3559' into bugfix/HOR-3467 2017-08-09 08:16:55 -04:00
Ronald Quenta
1b0514c941 Merged in bugfix/HOR-3465 (pull request #5869)
Bugfix/HOR-3465

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
Approved-by: Paula Quispe <paula.quispe@processmaker.com>
2017-08-08 21:54:28 +00:00
Ronald Quenta
38e9cc93fd add permissions 2017-08-08 15:00:21 -04:00
Ronald Quenta
61f9f9f7c4 add validation for sort and up observations 2017-08-08 14:46:01 -04:00
Roly Rudy Gutierrez Pinto
efe447643e HOR-3627 pull request observations 2017-08-08 13:54:51 -04:00
Roly Rudy Gutierrez Pinto
45c1ceffcc HOR-3627 2017-08-08 09:53:00 -04:00
Ronald Quenta
04a8b6561a HOR-3467 2017-08-07 16:33:49 -04:00
Ronald Quenta
496d590f42 Merge remote-tracking branch 'origin/feature/HOR-3560' into bugfix/HOR-3465 2017-08-07 16:13:26 -04:00
Paula Quispe
c366a68d37 Add permission for generateBpmn 2017-08-07 11:32:07 -04:00
Ronald Quenta
517fce5b3d review permissions 2017-08-07 02:37:39 -04:00
Ronald Quenta
70bbade5e0 add new exception 2017-08-07 02:20:05 -04:00
Ronald Quenta
3226096677 HOR-3465 2017-08-06 14:50:24 -04:00
Ronald Quenta
bf34ab8778 HOR-3465 2017-08-06 14:46:40 -04:00
Paula Quispe
0480444871 HOR-3383 2017-08-05 12:52:32 -04:00
Paula Quispe
f9d33e6451 Resolve conflict with Rbac and remove loads 2017-08-04 07:19:26 -04:00
Paula Quispe
9eb7d6cac2 HOR-2689 2017-08-03 17:00:30 -04:00
Paula Quispe
07d304780d HOR-3298 2017-07-05 10:16:53 -04:00
Paula Quispe
7fa1dc105e Merged in bugfix/HOR-3390 (pull request #5744)
HOR-3390

Approved-by: Julio Cesar Laura Avendaño <contact@julio-laura.com>
2017-07-03 19:36:00 +00:00
Paula Quispe
eb123d1729 HOR-3462 2017-06-30 10:20:51 -04:00
Paula Quispe
54193f0492 HOR-3390 2017-06-20 16:10:44 -04:00
Paula Quispe
42ac321495 HOR-3327 2017-06-14 11:21:09 -04:00
Julio Cesar Laura Avendaño
720e3eb458 Put security fixes to develop branch 2017-06-14 11:14:23 -04:00