Project

General

Profile

Actions

Bug #24690

closed

Editing user roles overrides tenants in rudder-users.xml file

Added by Clark ANDRIANASOLO 22 days ago. Updated 5 days ago.

Status:
Released
Priority:
N/A
Target version:
Severity:
Major - prevents use of part of Rudder | no simple workaround
UX impact:
I dislike using that feature
User visibility:
Operational - other Techniques | Rudder settings | Plugins
Effort required:
Very Small
Priority:
104
Name check:
To do
Fix check:
Checked
Regression:
No

Description

When editing users roles (removing or adding them) from the user management dashboard, the tenants attribute of the user in the rudder-users.xml file always disappears.
It may lead to security issues (also in the scope of API accounts) : no tenants attribute means that user has access to all tenants.

We need to keep the tenants attribute as is for every user when updating the rudder-users.xml file.

Actions #1

Updated by Clark ANDRIANASOLO 18 days ago

  • Status changed from New to In progress
Actions #2

Updated by Clark ANDRIANASOLO 18 days ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Clark ANDRIANASOLO to Vincent MEMBRÉ
  • Pull Request set to https://github.com/Normation/rudder-plugins/pull/701
Actions #3

Updated by Clark ANDRIANASOLO 16 days ago

  • Status changed from Pending technical review to Pending release
Actions #4

Updated by François ARMAND 7 days ago

  • Fix check changed from To do to Checked
Actions #5

Updated by Vincent MEMBRÉ 5 days ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder plugin user-management v8.1.1-2.2

Actions #6

Updated by Vincent MEMBRÉ 5 days ago

This bug has been fixed in Rudder plugin user-management v8.1.1-2.2

Actions

Also available in: Atom PDF