Actions
Bug #24690
closedEditing user roles overrides tenants in rudder-users.xml file
Pull Request:
Severity:
Major - prevents use of part of Rudder | no simple workaround
UX impact:
I dislike using that feature
User visibility:
Operational - other Techniques | Rudder settings | Plugins
Effort required:
Very Small
Priority:
104
Name check:
To do
Fix check:
Checked
Regression:
No
Description
When editing users roles (removing or adding them) from the user management dashboard, the tenants
attribute of the user in the rudder-users.xml
file always disappears.
It may lead to security issues (also in the scope of API accounts) : no tenants
attribute means that user has access to all tenants.
We need to keep the tenants
attribute as is for every user when updating the rudder-users.xml
file.
Actions