Project

General

Profile

Actions

Bug #26602

open

User with "compliance" perm get error on group, directive pages

Added by Nicolas CHARLES 7 days ago. Updated 4 days ago.

Status:
Pending release
Priority:
N/A
Category:
Web - Nodes & inventories
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
Yes

Description

When using a user with the "compliance" permission and only that one, when we get on a group detail, we have two errors regarding server error.

The same kind of error happens on directive, and rule, node (see screenshots).

=> only the compliance tab of nodes, rules, directives, groups should be accessible for a user with only compliance perm.

Plus that permission profile has access to techniques and global properties : he should not.

Seen in 8.3, but the behavior is likely also incorrect in 8.2.

It happens also on the node details

and the rules page


Files

clipboard-202503241411-ac1in.png (88.5 KB) clipboard-202503241411-ac1in.png Nicolas CHARLES, 2025-03-24 14:11
clipboard-202503241424-ml8rx.png (214 KB) clipboard-202503241424-ml8rx.png Nicolas CHARLES, 2025-03-24 14:24
clipboard-202503241425-irwu9.png (229 KB) clipboard-202503241425-irwu9.png Nicolas CHARLES, 2025-03-24 14:25
clipboard-202503271530-ojrig.png (354 KB) clipboard-202503271530-ojrig.png Clark ANDRIANASOLO, 2025-03-27 15:30
clipboard-202503271530-ec7z7.png (354 KB) clipboard-202503271530-ec7z7.png Clark ANDRIANASOLO, 2025-03-27 15:30

Related issues 2 (1 open1 closed)

Related to Rudder - Architecture #24872: Rework api authorization modelsReleasedVincent MEMBRÉActions
Related to Rudder - Bug #26642: Compliance right should not give access to techniques and global parametersPending technical reviewFrançois ARMANDActions
Actions

Also available in: Atom PDF