Bug 1127442

Summary: readonly user should not have "New Authentication Source" button on Administer > LDAP Authentication
Product: Red Hat Satellite Reporter: Corey Welton <cwelton>
Component: Users & RolesAssignee: satellite6-bugs <satellite6-bugs>
Status: CLOSED INSUFFICIENT_DATA QA Contact: Katello QA List <katello-qa-list>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 6.0.3CC: cwelton, dcleal
Target Milestone: Unspecified   
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-09-17 10:24:05 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Corey Welton 2014-08-06 20:49:00 UTC
Description of problem:
Readonly ("Viewer") user has "New Authentication Source" button in UI when navigating to LDAP Auth page.  This button does not function (user given perm denied) but it should be removed as per other pages accessible by readonly user.

Version-Release number of selected component (if applicable):
Satellite-6.0.4-RHEL-6-20140730.0

How reproducible:


Steps to Reproduce:
1. Create user 'readonly' with role 'Viewer'
2. Login with user 'readonly'
3. Nav to Administer > LDAP Authentication
4. View results

Actual results:
New Authentication Source button exists

Expected results:
Button should not exist for readonly user

Additional info:
I am not sure if this exists elsewhere in the UI, offhand, but we should check.

Comment 1 Corey Welton 2014-08-06 20:52:40 UTC
Also exists in: Host Groups

Comment 3 Dominic Cleal 2014-08-12 12:05:31 UTC
I'm not able to reproduce this, would you mind double checking the contents of the Viewer role, the Anonymous role, and the roles assigned to your user?