Project

General

Profile

Actions

Bug #9133

closed

Quicksearch does not enforce user authorizations

Added by Alexis Mousset over 7 years ago. Updated almost 5 years ago.

Status:
Released
Priority:
N/A
Category:
Web - Config management
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
Fix check:
Regression:

Description

An inventory users gets, for example, access to all directive parameters through the quicksearch.

Actions #1

Updated by François ARMAND over 7 years ago

Can someone list the expected roles with limitations (and the limitations ?)

Actions #2

Updated by Vincent MEMBRÉ over 7 years ago

Right list is :
"node", "group", "deployment", "administration", "configuration", "rule", "technique", "directive", "validator", "deployer"

I guess we can only keep

"node", "group", "rule", "directive"

Maybe 'configuration' can be added (it always define 'rule' and 'directive' access)
But the mapping is clear for almost, and "parameters" should be accessed if Directive read rights are granted

Actions #3

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from New to In progress
  • Assignee set to Vincent MEMBRÉ
Actions #4

Updated by François ARMAND over 7 years ago

OK, so let say:

- "configuration" gives rules, techniques, directives, parameters,
- "rule" gives access to rules,
- "directive" gives access to techniques, directives, parameters,
- "group" to groups,
- "node" to nodes

Actions #5

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Vincent MEMBRÉ to François ARMAND
  • Pull Request set to https://github.com/Normation/rudder/pull/1209
Actions #6

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from Pending technical review to Pending release
  • % Done changed from 0 to 100
Actions #7

Updated by Vincent MEMBRÉ over 7 years ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 3.1.15/14 and 3.2.8/7 which were released today.

Actions #8

Updated by Vincent MEMBRÉ almost 5 years ago

  • Private changed from Yes to No
  • Priority set to 0
Actions

Also available in: Atom PDF