Bug 1699943

Summary: RBAC: User unable to retire the service when role is EVMRole-user_self_service
Product: Red Hat CloudForms Management Engine Reporter: Niyaz Akhtar Ansari <nansari>
Component: APIAssignee: drew uhlmann <duhlmann>
Status: CLOSED CURRENTRELEASE QA Contact: Niyaz Akhtar Ansari <nansari>
Severity: high Docs Contact: Red Hat CloudForms Documentation <cloudforms-docs>
Priority: medium    
Version: 5.10.3CC: bmidwood, dmetzger, duhlmann, hkataria, lavenel, obarenbo, simaishi, tfitzger, yrudman
Target Milestone: GAKeywords: TestOnly, ZStream
Target Release: 5.11.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: 5.11.0.7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1763860 (view as bug list) Environment:
Last Closed: 2019-12-13 14:54:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: Bug
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1763860    
Attachments:
Description Flags
screenshot
none
mapping of ops/sui roles -- OLD none

Description Niyaz Akhtar Ansari 2019-04-15 13:05:27 UTC
Created attachment 1555230 [details]
screenshot

Description of problem:

A user with EVMRole-user_self_service role not able to retire the service but when I enabled the "Approve and Deny" permission is here in role so user able to retire the service.

Version-Release number of selected component (if applicable):
Version: 5.10.3.2.20190410215422_59d5d16

How reproducible:
100%

Steps to Reproduce:
1. Copy role "EVMRole-user_self_service" and "Access Restriction for Services, VMs, and Templates" set to "None"
2. Create Group and users 
2. Create service as the "admin" user or non-admin user  
3. ordered the service
4. Login to ssui portal as above created non-admin user 
5. Retire the Service


Actual results:
Toast Notifications appears with error message "There was an error removing one or more services." 


Expected results:


Additional info:

Comment 5 drew uhlmann 2019-04-16 19:36:00 UTC
The stack trace:
MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/bundler/gems/cfme-api-3e9150d0c9d6/app/controllers/api/base_controller/authentication.rb:73:in `validate_user_identity'
log/api.log:[----] E, [2019-04-16T15:25:36.998719 #15214:39a1250] ERROR -- : MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/bundler/gems/cfme-api-3e9150d0c9d6/app/controllers/api/base_controller/authentication.rb:86:in `auth_user'
log/api.log:[----] E, [2019-04-16T15:25:36.998735 #15214:39a1250] ERROR -- : MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/bundler/gems/cfme-api-3e9150d0c9d6/app/controllers/api/base_controller/authentication.rb:101:in `authenticate_with_user_token'
log/api.log:[----] E, [2019-04-16T15:25:36.998750 #15214:39a1250] ERROR -- : MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/bundler/gems/cfme-api-3e9150d0c9d6/app/controllers/api/base_controller/authentication.rb:27:in `require_api_user_or_token'
log/api.log:[----] E, [2019-04-16T15:25:36.998796 #15214:39a1250] ERROR -- : MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/gems/activesupport-5.0.7.2/lib/active_support/callbacks.rb:382:in `block in make_lambda'
log/api.log:[----] E, [2019-04-16T15:25:36.998812 #15214:39a1250] ERROR -- : MIQ(Api::ServicesController.api_error) /opt/rh/cfme-gemset/gems/activesupport-5.0.7.2/lib/active_support/callbacks.rb:150:in `block (2 levels) in halting_and_conditional'

I'm seeing errors about [Couldn't find User with 'id'=34] which makes sense since there's 1 and 35, I'm looking more into it.

Comment 6 drew uhlmann 2019-04-17 12:19:03 UTC
Created attachment 1555887 [details]
mapping of ops/sui roles -- OLD

This needs to get updated to include approval for retirement and provisioning and approval in general and that's a call that's probably in the hands of someone like Loic... I also am not sure what else is missing on this sheet but it's pretty old, and I feel like maybe there are other things. So it'd be great to have someone with power take a look at this.

Comment 7 drew uhlmann 2019-04-17 18:59:30 UTC
I'd like to say for the record that, as a non-admin user you can see an admin user's services from the SUI ... that feels bad. The fact that you're supposed to be able to retire the services feels even more wrong.

Comment 8 drew uhlmann 2019-05-07 12:33:15 UTC
Hey Tina, I have some questions on the expected behavior of this ticket and I was wondering if you could help me get them answered please.

Comment 10 drew uhlmann 2019-05-16 19:12:18 UTC
After discussion with Tina, I think that we have a bigger issue regarding approval than the scope of what this ticket appears to be open for. Because of that, I don't believe it's actionable at the moment.

Comment 13 drew uhlmann 2019-05-23 17:56:12 UTC
Could you please retest with a user that also has the permission Everything -> Services -> Requests -> Operate -> approve and deny ?

Comment 14 Niyaz Akhtar Ansari 2019-05-24 06:39:03 UTC
Drew,
 
Yes user can retire the service when we give approve and deny permission to user.
I have already mentioned in bz description.

"A user with EVMRole-user_self_service role not able to retire the service but when I enabled the "Approve and Deny" permission is here in role so user able to retire the service"

Comment 15 drew uhlmann 2019-05-28 19:27:26 UTC
https://github.com/ManageIQ/manageiq-api/pull/599

Comment 16 Niyaz Akhtar Ansari 2019-06-14 12:09:59 UTC
able to retire the service when role is EVMRole-user_self_service

Verified in Version 5.11.0.8.20190611155126_01e077e