[KULRICE-10773] Add permission check the Transactional Document copy method Created: 27/Sep/13  Updated: 24/Sep/14  Resolved: 08/Sep/14

Status: Closed
Project: Kuali Rice Development
Component/s: Development, KNS Equivalency
Affects Version/s: None
Fix Version/s: 2.5
Security Level: Public (Public: Anyone can view)

Type: Bug Fix Priority: Major
Reporter: Jeff Ruch Assignee: Martin Taylor (Inactive)
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Cloners
cloned from KULRICE-10772 Support "Use Transactional Document" ... Closed
cloned to KULRICE-10774 Remove isSessionDocument() method and... Open
Discovered
discovered KULRICE-13166 Investigate better option to material... Open
Rice Module:
KRAD
KRAD Feature Area:
Maintenance
Application Requirement:
Rice
Sprint: Core 2.5.0-m6 Sprint 2, Core 2.5.0-m7 Sprint 1
KAI Review Status: Not Required
KTI Review Status: Not Required
Code Review Status: Not Required
Include in Release Notes?:
Yes
Story Points: 3

 Description   

The copy method is in the controller but it is missing the (warning) Permission check is missing in the transactional document controller.

Item T2 on https://docs.google.com/a/kuali.org/spreadsheet/ccc?key=0AqaSaSLMsdRMdGUxREo4UXRBN1FjN1Fyb1Bvb3JhWUE#gid=0



 Comments   
Comment by Claus Niesen [ 11/Aug/14 ]

The Travel Authorization document in the KRAD Demo App is a transactional document.

Comment by Martin Taylor (Inactive) [ 15/Aug/14 ]

Notes:

  • TransactionalDocumentControllerBase is currently calling cancelAttachment - to be fixed
  • Rice Routing Rule Screens use edit/copy, good cases to compare for kns functionality
  • org.kuali.rice.krad.service.impl.MaintenanceDocumentServiceImpl#setupNewMaintenanceDocument shows checks on canCreate for new and copy actions.
  • Can use travel authorization document lookup view as entry point to test copy
Comment by Martin Taylor (Inactive) [ 27/Aug/14 ]

Regarding permission:

  • the copy action functionality was handled via a permissions check in the action. In KRAD, it goes through the UifControllerHandlerInterceptor but only if its a post. Added post to the method to call to ensure its working properly.
  • Original copy method to call was using 'maintenanceCopy' call. But transactional was tied to 'copy'. When reviewing KRADConstants, 'copy' was listed as Mainteance_copy_method_to_call, and standard copy_to_call was set to 'maintenanceCopy'. Added Document to KradConstants and set method_to_call_copy = 'copy'.
  • Some JPA/OJB issues with copy functionality, corrected.

Adding code review with Kristina/Jonathan

Generated at Sun Jan 24 12:04:19 CST 2021 using JIRA 7.0.11#70121-sha1:19d24976997c1d95f06f3e327e087be0b71f28d4.