Bug 1022379 - Group member can modify jobs submitted by others
Summary: Group member can modify jobs submitted by others
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Beaker
Classification: Retired
Component: web UI
Version: develop
Hardware: Unspecified
OS: Unspecified
unspecified
high vote
Target Milestone: ---
Assignee: beaker-dev-list
QA Contact: tools-bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-10-23 07:50 UTC by wangjing
Modified: 2018-02-06 00:41 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-10-24 02:55:05 UTC


Attachments (Terms of Use)

Description wangjing 2013-10-23 07:50:36 UTC
Description of problem:
groupmember could modify some  jobs submitted by others

Version-Release number of selected component (if applicable):
beaker-devel Version 0.15.1rc1

How reproducible:
some jobs

Steps to Reproduce:
1. account1(xjia) submit some jobs(j:1738/1739/1740/1741/1742)
2. account2(shajiang) joined in the group xjia which account1 was in.
3. account2 login and try to edit the jobs' whiteboard.

Actual results:
account2 can edit the jobs submitted by xjia.


Expected results:
account2 can't edit these non-group jobs.

Additional info:

Comment 2 Amit Saha 2013-10-23 13:56:51 UTC
Are you saying that other group members should not be able to edit any details in another members' job? The documentation at [1] states the following "By default the submitter is the only person who can modify the job (except for any member of any group the submitter belongs to; they can ack/nack the job)." Does that also extend to editing the whiteboard? I will let someone else clarify.


[1] http://beaker-project.org/docs/user-guide/job-design.html#access-control-for-jobs

Comment 3 Raymond Mancy 2013-10-24 02:55:05 UTC
This is more or less expected behaviour. Please see bz#1000861.

If a system is still configured to use the old behaviour, those docs that Amit linked to do not apply.

I've created this bug (bz#1022776) to deal with the Docs problem.


Note You need to log in before you can comment on or make changes to this bug.