B2B User Is Able To Access Site Which Doesn't Have a Contract Associated with the Account
(Doc ID 2554922.1)
Last updated on NOVEMBER 22, 2019
Applies to:
Oracle Commerce Cloud Service - Version N/A to N/AInformation in this document applies to any platform.
Symptoms
B2B user (contact added in account) is able to access site which does not have a contract with that Account.
Steps to Reproduce:
- Go to https:/ccstore....com/ABC
- Login in with b2b user that has a cotract with site ABC
- Now navigate to a second site in that same session https:/ccstore....com/XYZ or select XYZ link (for which the b2b users does not have a contract)
- USER is still logged in even though the account does not have contract with XYZ
Changes
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Changes |
Cause |
Solution |
References |