Project

General

Profile

Actions

User story #10764

open

Technique editor ignores Rudder's CR process

Added by Florian Heigl over 7 years ago. Updated almost 3 years ago.

Status:
New
Priority:
N/A
Assignee:
-
Category:
Web - Technique editor
Target version:
-
UX impact:
Suggestion strength:
User visibility:
Operational - other Techniques | Technique editor | Rudder settings
Effort required:
Large
Name check:
Fix check:
Regression:

Description

If you hand configuration permissions to a rudder user, they are be allowed to view, modify and debug the configuration that makes up rudder's end system policy.
Unfortunately it seems if they have access to NCF they are able to modify contents of the techniques in there.
The problem is that those changes take effect directly, and bypass the CR system.

This shouldn't be too hard to solve just modifying the type of input boxes and disabling visually the save + reset buttons.

Until then, it needs to be documented, along with advice on how to set up (or, rather, which permissions to not hand out) NCF.
NCF is no longer a beta component as far as I am aware and shouldn't just ignore rudder.

My suggestion is to properly introduce versioning on NCF techniques.

That way modification of an rule-contained NCF technique could be allowed but not have any effect on the live policy, forcing to switch it's version from within the Rudder side of things.
That would then need to pass through the CR process.

Not that I like it too much, but it would actually allow to create and prepare the objects in NCF and not get in the way until they are really affecting systems.

In any case, a warning needs to move in place.


Related issues 1 (0 open1 closed)

Related to Rudder - Bug #14312: Missing eventlogs for technique editor action and technique updateReleasedFrançois ARMANDActions
Actions #1

Updated by François ARMAND over 7 years ago

  • Severity changed from Major - prevents use of part of Rudder | no simple workaround to Critical - prevents main use of Rudder | no workaround | data loss | security
  • User visibility changed from Infrequent - complex configurations | third party integrations to Operational - other Techniques | Technique editor | Rudder settings
  • Effort required set to Large
  • Priority changed from 0 to 46
Actions #2

Updated by Benoît PECCATTE over 7 years ago

  • Priority changed from 46 to 45
Actions #3

Updated by Benoît PECCATTE about 7 years ago

  • Priority changed from 45 to 42
Actions #4

Updated by François ARMAND almost 6 years ago

  • Related to Bug #14312: Missing eventlogs for technique editor action and technique update added
Actions #5

Updated by Alexis Mousset almost 6 years ago

  • Subject changed from ncf ignores rudder's CR process. to Technique editor ignores Rudder's CR process
  • Priority changed from 42 to 0
Actions #6

Updated by Alexis Mousset almost 3 years ago

  • Tracker changed from Bug to User story
  • Severity deleted (Critical - prevents main use of Rudder | no workaround | data loss | security)
  • Priority deleted (0)
Actions

Also available in: Atom PDF