Bug 1012591

Summary: RBAC: Scoped properties - buttons visible for roles without permissions
Product: [JBoss] JBoss Enterprise Application Platform 6 Reporter: Jakub Cechacek <jcechace>
Component: Web ConsoleAssignee: Heiko Braun <hbraun>
Status: CLOSED CURRENTRELEASE QA Contact: Jakub Cechacek <jcechace>
Severity: urgent Docs Contact: Russell Dickenson <rdickens>
Priority: unspecified    
Version: 6.2.0CC: brian.stansberry, dosoudil, hpehl, jkudrnac
Target Milestone: ER4   
Target Release: EAP 6.2.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-12-15 16:16:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1014047    

Description Jakub Cechacek 2013-09-26 17:08:58 UTC
Add / remove buttons are visible for some roles which actually don't have the permission to create / remove System properties scoped to Group / Host / Server. 

Example - maintainer role scoped to main server group + Serve / Group scoped system properties

Comment 1 Jakub Cechacek 2013-09-27 07:59:45 UTC
User without permission can also try to create the role, however the operation will fail on server side.

Comment 2 JBoss JIRA Server 2013-10-01 09:35:47 UTC
Heiko Braun <ike.braun> updated the status of jira HAL-233 to Resolved

Comment 3 Vladimir Dosoudil 2013-10-01 12:07:20 UTC
Moving back to ASSIGNED (https://docspace.corp.redhat.com/docs/DOC-154626).
There's no PR to eap 6.x github repo https://github.com/jbossas/jboss-eap/

Comment 4 Vladimir Dosoudil 2013-10-01 12:49:01 UTC
The umbrella issue 1014047 is available now.

Comment 8 Jakub Cechacek 2013-10-09 07:59:55 UTC
Verified 6.2.0.ER5