Uploaded image for project: 'OpenMRS Core'
  1. OpenMRS Core
  2. TRUNK-3711

Incorrect permissions on encounter role service methods

    Details

    • Complexity:
      Low

      Description

      In the EncounterService, we incorrectly have the Manage Encounter Roles privilege on methods that should have View Encounter Roles privileges instead:

      @Authorized( { PrivilegeConstants.MANAGE_ENCOUNTER_ROLES })
      public List<EncounterRole> getAllEncounterRoles(boolean includeRetired);
      
      @Authorized( { PrivilegeConstants.MANAGE_ENCOUNTER_ROLES })
      public EncounterRole getEncounterRoleByUuid(String uuid) throws APIException;
      

        Attachments

          Activity

            People

            • Assignee:
              lluismf Lluis Martinez [X] (Inactive)
              Reporter:
              mseaton Mike Seaton
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - 30 minutes
                30m
                Remaining:
                Time Spent - 15 minutes Remaining Estimate - 15 minutes
                15m
                Logged:
                Time Spent - 15 minutes Remaining Estimate - 15 minutes
                15m