Project

General

Profile

Actions

Bug #26952

open

User with only  “Inventory” rights can access too much information

Added by Michel BOUISSOU 5 days ago.

Status:
New
Priority:
To review
Assignee:
-
Category:
Web - UI & UX
Target version:
Severity:
Major - prevents use of part of Rudder | no simple workaround
UX impact:
I hate Rudder for that
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

A ˘toto" user, created with only “Inventory” rights can access a lot more :

- System updates
- Nodes properties
- Node technical logs (that may show sensitive information)

Plus clicking on many tabs produce an error message :

Error
Error when Getting node compliance, details:
Unknown error

Even though some content gets displayed


Files

User_toto_250522a.png (49.6 KB) User_toto_250522a.png Toto only has inventory rights Michel BOUISSOU, 2025-05-23 16:55
User_inventory_access_250522a_updates.png (211 KB) User_inventory_access_250522a_updates.png Toto can see system updates Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522b_properties.png (189 KB) User_inventory_access_250522b_properties.png Toto can see nodes properties Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522c_tech_logs.png (263 KB) User_inventory_access_250522c_tech_logs.png Toto can see technical logs Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522d_error.png (8.2 KB) User_inventory_access_250522d_error.png Error message often displayed Michel BOUISSOU, 2025-05-23 16:56

No data to display

Actions

Also available in: Atom PDF