Bug 1132665

Summary: User w/o view host permission can access /hosts UI page
Product: Red Hat Satellite Reporter: Tom McKay <tomckay>
Component: WebUIAssignee: Tom McKay <tomckay>
Status: CLOSED ERRATA QA Contact: Kedar Bidarkar <kbidarka>
Severity: low Docs Contact:
Priority: unspecified    
Version: 6.0.4CC: bbuckingham, dcleal, kbidarka, sthirugn, xdmoon
Target Milestone: UnspecifiedKeywords: Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
URL: http://projects.theforeman.org/issues/7218
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-12 05:15:22 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 971511    

Description Tom McKay 2014-08-21 19:16:44 UTC
A user w/o view host permission should be prevented from visiting /hosts UI page

Comment 1 Tom McKay 2014-08-21 19:16:45 UTC
Created from redmine issue http://projects.theforeman.org/issues/7218

Comment 3 Bryan Kearney 2014-08-29 18:04:17 UTC
Upstream bug assigned to tomckay

Comment 4 Bryan Kearney 2014-09-02 08:04:50 UTC
Moving to POST since upstream bug http://projects.theforeman.org/issues/7218 has been closed
-------------
Thomas McKay
Applied in changeset commit:cb3faecd7153927c8ef856f1a9475712c74ecb8e.

Comment 7 Kedar Bidarkar 2015-02-13 08:12:10 UTC
Tested with Sat6.1 Beta-snap2:

We no longer see the '/hosts' page without the "view host" permission.

Comment 8 Bryan Kearney 2015-08-11 13:23:43 UTC
This bug is slated to be released with Satellite 6.1.

Comment 9 errata-xmlrpc 2015-08-12 05:15:22 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2015:1592