Quantcast
Channel: NAV Three Tier — mibuso.com
Viewing all articles
Browse latest Browse all 10032

NAV 2016 Web client URL - Changing Company Name in url ignores NAV security

$
0
0
We have installed and configured NAV 2016 web client. Works fine.
However, it appears to be possible to simply change the company name element of the url and this by-passes NAV security.
Example:
Two NAV companies, Company A and Company B
User only has access to Company A as per NAV security permissions
URL for web client is https://xxxxxxx/yyy/WebClient/?company=Company A but if user changes url to https://xxxxxxx/DEV/WebClient/?company=Company B then then can access Company B, overriding security.
If they try to change company via 'My Settings' they (correctly) get an error.

Viewing all articles
Browse latest Browse all 10032

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>