Project

General

Profile

Actions

Bug #26952

open

User with only  “Inventory” rights has a notification error when changing tab

Added by Michel BOUISSOU 30 days ago. Updated 9 days ago.

Status:
Pending release
Priority:
1 (highest)
Category:
Web - UI & UX
Target version:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
I hate Rudder for that
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

A ˘toto" user, created with only “Inventory” rights can access a lot more :

- System updates
- Nodes properties
- Node technical logs (that may show sensitive information)

Plus clicking on many tabs produce an error message :

Error
Error when Getting node compliance, details:
Unknown error

Even though some content gets displayed


Files

User_toto_250522a.png (49.6 KB) User_toto_250522a.png Toto only has inventory rights Michel BOUISSOU, 2025-05-23 16:55
User_inventory_access_250522a_updates.png (211 KB) User_inventory_access_250522a_updates.png Toto can see system updates Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522b_properties.png (189 KB) User_inventory_access_250522b_properties.png Toto can see nodes properties Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522c_tech_logs.png (263 KB) User_inventory_access_250522c_tech_logs.png Toto can see technical logs Michel BOUISSOU, 2025-05-23 16:56
User_inventory_access_250522d_error.png (8.2 KB) User_inventory_access_250522d_error.png Error message often displayed Michel BOUISSOU, 2025-05-23 16:56
clipboard-202506051548-ddp9w.png (96 KB) clipboard-202506051548-ddp9w.png Clark ANDRIANASOLO, 2025-06-05 15:48
clipboard-202506051548-7hy8k.png (96 KB) clipboard-202506051548-7hy8k.png Clark ANDRIANASOLO, 2025-06-05 15:48

Related issues 1 (1 open0 closed)

Related to Rudder - Bug #27040: Inventory role allows to get system compliance and technical logs Pending releaseClark ANDRIANASOLOActions
Actions

Also available in: Atom PDF