axelor / axelor-open-platform

Open source Java framework for business application development
http://axelor.com
Other
391 stars 298 forks source link

Multi tenancy app account security #75

Open Cedric-Guerrier opened 3 years ago

Cedric-Guerrier commented 3 years ago

Hi,

If we using multi tenancy, when we are connected with one account with no roles filter, we can switch tenant without password control. If password is same why not ( like peer authentification ) but if password is different, it's a security breach.

Axelor Open Platform version 5.3.5.

Regards.