Bug 1428131

Summary: limit list of user's roles to for creating a group
Product: Red Hat CloudForms Management Engine Reporter: Satoe Imaishi <simaishi>
Component: UI - OPSAssignee: Libor Pichler <lpichler>
Status: CLOSED ERRATA QA Contact: Matouš Mojžíš <mmojzis>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 5.8.0CC: aperotti, hkataria, jhardy, mmojzis, mpovolny, obarenbo, simaishi
Target Milestone: GAKeywords: ZStream
Target Release: 5.7.2   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: appliance:configuration:rbac:ui
Fixed In Version: 5.7.2.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1426619 Environment:
Last Closed: 2017-04-12 14:40:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1426619    
Bug Blocks:    

Comment 2 CFME Bot 2017-03-08 19:31:01 UTC
New commit detected on ManageIQ/manageiq/euwe:
https://github.com/ManageIQ/manageiq/commit/4b43ce246836e83f61312775b8a934c5b946a43c

commit 4b43ce246836e83f61312775b8a934c5b946a43c
Author:     Gregg Tanzillo <gtanzill>
AuthorDate: Mon Feb 27 17:14:32 2017 -0500
Commit:     Satoe Imaishi <simaishi>
CommitDate: Wed Mar 8 14:28:35 2017 -0500

    Merge pull request #14081 from lpichler/remove_admin_role_for_tenant_admin
    
    Remove admin role for tenant admin
    (cherry picked from commit 8036eda9632d64d635401ef6c1a747e9e1ee084c)
    
    https://bugzilla.redhat.com/show_bug.cgi?id=1428131

 lib/rbac/filterer.rb           | 2 +-
 spec/lib/rbac/filterer_spec.rb | 8 ++++++--
 2 files changed, 7 insertions(+), 3 deletions(-)

Comment 4 Matouš Mojžíš 2017-03-28 15:53:27 UTC
Verified in 5.7.2.0. I can't create anymore group with higher permissions than tenant-admin has.

Comment 6 errata-xmlrpc 2017-04-12 14:40:58 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2017:0898