Bug 1414912
Summary: | User with Viewer role are not able to view subscriptions and settings | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Satellite | Reporter: | Konstantin Trufanov <ktrufano> | ||||||
Component: | Users & Roles | Assignee: | satellite6-bugs <satellite6-bugs> | ||||||
Status: | CLOSED DUPLICATE | QA Contact: | Katello QA List <katello-qa-list> | ||||||
Severity: | high | Docs Contact: | |||||||
Priority: | unspecified | ||||||||
Version: | 6.2.6 | CC: | bbuckingham, bkearney, dhlavacd, ktrufano, mhulan | ||||||
Target Milestone: | Unspecified | ||||||||
Target Release: | Unused | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Doc Type: | If docs needed, set a value | |||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2017-02-10 08:46:06 UTC | Type: | Bug | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Attachments: |
|
Created attachment 1242536 [details]
hammer errors
Hello, there are two parts here, settings and view subscriptions. Settings can be only viewed by administrator which is intentional. Settings are global for all organization and can be viewer more like application configuration, therefore non-admin users should not be able to see it or manipulate it. Regarding subscriptions, it can be either caused by the fact that Viewer role does not contain view_subscriptions permissions (BZ 1304608) or by the fact that view_subscriptions permission is broken (BZ 1333219). So I suggest to verify whether customer can see a filter with resource type Organization and permission with view_subscriptions in Viewer role. It's not clear from "User with Viewer role can't list subscriptions and settings although it has correct filters set" If they can not, close as dup of BZ 1304608, otherwise close as dup of BZ 1333219. Btw the removal of access_setting permission is being tracked by this upstream issue http://projects.theforeman.org/issues/18440 *** This bug has been marked as a duplicate of bug 1333219 *** |
Created attachment 1242535 [details] webui error Description of problem: User with Viewer role can't list subscriptions and settings although it has correct filters set Version-Release number of selected component (if applicable): 6.2.4 How reproducible: WebUI and hammer Steps to Reproduce: 1. Create user with Viewer role 2. List subscriptions or settings via hammer or WebUI Actual results: User are not able to view subscriptions and settings Expected results: User able to view subscriptions and settings Additional info: There is different errors for settings and subscriptions For settings: Hammer - 403 Forbidden - server refused to process the request WebUI - No such menu at all For subscriptions: WebUI - 403 error (see attached screenshot) Hammer - return empty results