Project

General

Profile

Actions

Bug #27040

open

Inventory role allows to get system compliance and technical logs

Added by Clark ANDRIANASOLO 1 day ago. Updated 1 day ago.

Status:
Pending technical review
Priority:
N/A
Category:
Security
Target version:
Severity:
Minor - inconvenience | misleading | easy workaround
UX impact:
User visibility:
Getting started - demo | first install | Technique editor and level 1 Techniques
Effort required:
Very Small
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

As a user with "inventory" role, I can open the system compliance of a node and see the content of the Technical logs tab (as in #26952), as well as all system components, and logs in the System status tab :

The inventory role should not allow to see the content of both tabs


Files

clipboard-202506051551-lampj.png (188 KB) clipboard-202506051551-lampj.png Clark ANDRIANASOLO, 2025-06-05 15:51

Related issues 1 (1 open0 closed)

Related to Rudder - Bug #26952: User with only  “Inventory” rights has a notification error when changing tabPending technical reviewClark ANDRIANASOLOActions
Actions #1

Updated by Clark ANDRIANASOLO 1 day ago

  • Description updated (diff)
Actions #2

Updated by Clark ANDRIANASOLO 1 day ago

  • Description updated (diff)
Actions #3

Updated by Clark ANDRIANASOLO 1 day ago

  • Related to Bug #26952: User with only  “Inventory” rights has a notification error when changing tab added
Actions #4

Updated by Clark ANDRIANASOLO 1 day ago

  • Status changed from New to In progress
Actions #5

Updated by Clark ANDRIANASOLO 1 day ago

  • Status changed from In progress to Pending technical review
  • Pull Request set to https://github.com/Normation/rudder/pull/6432
Actions

Also available in: Atom PDF