Bug 1562775

Summary: Approval permissions are not followed between different groups
Product: Red Hat CloudForms Management Engine Reporter: Satoe Imaishi <simaishi>
Component: ApplianceAssignee: Libor Pichler <lpichler>
Status: CLOSED ERRATA QA Contact: Landon LaSmith <llasmith>
Severity: high Docs Contact:
Priority: high    
Version: 5.8.0CC: abellott, cpelland, jhardy, obarenbo, smallamp
Target Milestone: GAKeywords: ZStream
Target Release: 5.8.4   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: 5.8.4.2 Doc Type: Release Note
Doc Text:
This RBAC addition needs to be documented for customers. Changed: Now option Access Restriction for Services, VMs, and Templates in user's role User and Group owned role setting or Only User owned role setting is affecting also MiqRequests. So if you have selected User and Group owned role setting you will see requests of created by users which are in group which is current for logged user. User and Group owned role setting you will see only users requests.
Story Points: ---
Clone Of: 1545395 Environment:
Last Closed: 2018-06-25 14:19:13 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core Target Upstream Version:
Embargoed:
Bug Depends On: 1545395    
Bug Blocks: 1551709    

Comment 4 Landon LaSmith 2018-05-21 19:19:54 UTC
VERIFIED in 5.8.4.3. I was able to create two groups/users (userA & userB) with User/Group ownership restrictions. Approval requests created by admin or userA were not visible to userB.

Comment 6 errata-xmlrpc 2018-06-25 14:19:13 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:1972