Bug 1929140

Summary: Authentication enabled in web console
Product: Migration Toolkit for Virtualization Reporter: Fabien Dupont <fdupont>
Component: User ExperienceAssignee: Mike Turley <mturley>
Status: CLOSED ERRATA QA Contact: Amos Mastbaum <amastbau>
Severity: high Docs Contact: Avital Pinnick <apinnick>
Priority: high    
Version: 2.0.0CC: mturley
Target Milestone: ---   
Target Release: 2.1.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-08-26 07:09:08 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Fabien Dupont 2021-02-16 09:57:30 UTC
Description of problem:

The provider inventory contains information about the provider layout and this can be considered sensitive by some users.

It would be better to add an authentication layer to the inventory service to limit access to authenticated users. The UI impersonates the logged in user, hence can then access the inventory.

Comment 1 Mike Turley 2021-04-06 16:29:24 UTC
The UI end of this is already implemented (see https://github.com/konveyor/forklift-ui/issues/456#issuecomment-814256431), so only the backend changes remain.

Comment 2 Jeff Ortel 2021-04-06 20:23:08 UTC
Created this issue for the validation service: https://github.com/konveyor/forklift-validation/issues/21.

Comment 3 Fabien Dupont 2021-06-24 07:10:11 UTC
I have created BZ 1975654 to track the validation service implementation. Moving this BZ to MODIFIED.

Comment 4 Fabien Dupont 2021-06-24 21:51:52 UTC
Please test with the mtv-operator-bundle-2.1.0-5 build / iib:85044.

Comment 5 Amos Mastbaum 2021-08-12 08:25:32 UTC
verified 2.1.0-44

Comment 8 errata-xmlrpc 2021-08-26 07:09:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Migration Toolkit for Virtualization 2.1.0), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2021:3278