Bug 1411702

Summary: User access filtering using tags for clouds networks and floating ip| isnt' working as expected.
Product: Red Hat CloudForms Management Engine Reporter: Prasad Mukhedkar <pmukhedk>
Component: ApplianceAssignee: Libor Pichler <lpichler>
Status: CLOSED CURRENTRELEASE QA Contact: Ruslana Babyuk <rbabyuk>
Severity: high Docs Contact:
Priority: high    
Version: 5.7.0CC: abellott, akarol, jhardy, jritenou, obarenbo, pmukhedk, simaishi
Target Milestone: GAKeywords: TestOnly, ZStream
Target Release: 5.8.0   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: 5.8.0.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1427520 (view as bug list) Environment:
Last Closed: 2017-06-12 16:13:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1427520    

Description Prasad Mukhedkar 2017-01-10 11:02:49 UTC
Description of problem:

Networks and floating_ips are accessible to all the user irrespective 
what filtering is set. 


Version-Release number of selected component (if applicable):
cfme 5.7

How reproducible:
always

Steps to Reproduce:
- Create a group and set "Assigned Filters (read only)"
  to a visibility tag. 

- Attach that visibility tag to some networks and floting_ip

- create a user in the group and login using that user.


Actual results:
Under Networks, User can see all the network. (visibility filter is simply)

Expected results:
Should only show the networks for which the user has visibility



Additional info:

Comment 2 Prasad Mukhedkar 2017-01-10 11:07:46 UTC
video recording of the buggy behavior has been attached to the bugzilla

Comment 4 jritenou 2017-02-04 00:42:41 UTC
I can also confirm this behavior just as Prasad stated:

1. Assign tag to cloud network/vpc/subnet.
2. Try to access resources with group with different tag filter.
3. Group can see all network resources regardless of tag.

It appears to just be resources under the network provider - I have confirmed it with both Azure & AWS cloud network resources.  

I'll see if I can get a video of it recorded over the weekend.

Comment 8 Ruslana Babyuk 2017-05-03 10:50:12 UTC
Verified in 5.8.0.13