Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1213840 - RBAC: User able to modify catalog items when it has only access to view permission
RBAC: User able to modify catalog items when it has only access to view permi...
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: UI - OPS (Show other bugs)
5.4.0
Unspecified Unspecified
medium Severity medium
: GA
: 5.6.0
Assigned To: Jozef Zigmund
Aziza Karol
rbac:service:catalog
:
Depends On:
Blocks: 1291456
  Show dependency treegraph
 
Reported: 2015-04-21 08:15 EDT by Aziza Karol
Modified: 2016-06-29 10:54 EDT (History)
6 users (show)

See Also:
Fixed In Version: 5.6.0.2
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1291456 (view as bug list)
Environment:
Last Closed: 2016-06-29 10:54:02 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
product feature (98.13 KB, image/png)
2015-04-21 08:15 EDT, Aziza Karol
no flags Details
snp1 (90.09 KB, image/png)
2015-04-21 08:15 EDT, Aziza Karol
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:1348 normal SHIPPED_LIVE CFME 5.6.0 bug fixes and enhancement update 2016-06-29 14:50:04 EDT

  None (edit)
Description Aziza Karol 2015-04-21 08:15:05 EDT
Created attachment 1016816 [details]
product feature

Description of problem:


Version-Release number of selected component (if applicable):
5.4.0.0.22.20150420163946_26004d1

How reproducible:
100%

Steps to Reproduce:
1. Create role, assign permissions for "Services", "Catalog Explorer", "Catalog Items", "View catalog Items" only
2.create a group and assign this role 
3.create user with the above role
4. Log in as the user

Actual results:
User is able to add new button group, add new buttons etc when is has only view permission. see attached screenshots

Expected results:
user should only be able to view items

Additional info:
Comment 1 Aziza Karol 2015-04-21 08:15:49 EDT
Created attachment 1016817 [details]
snp1
Comment 7 Jozef Zigmund 2015-09-14 10:31:29 EDT
Not sure why CFME Bot added that PR, because it's not related to the BZ.

Related Pull Request is https://github.com/ManageIQ/manageiq/pull/3987
Comment 11 CFME Bot 2016-04-13 14:31:04 EDT
New commit detected on ManageIQ/manageiq/master:
https://github.com/ManageIQ/manageiq/commit/2dfc3fbee7376844342e5fabaed8e809002d46fb

commit 2dfc3fbee7376844342e5fabaed8e809002d46fb
Author:     Jozef Zigmund <jzigmund@redhat.com>
AuthorDate: Tue Mar 15 17:00:53 2016 +0100
Commit:     Jozef Zigmund <jzigmund@redhat.com>
CommitDate: Thu Apr 7 15:47:58 2016 +0200

    Hide toolbar Add/Edit actions in CatalogItem#show when user has view permission only
    
    https://bugzilla.redhat.com/show_bug.cgi?id=1213840

 app/helpers/application_helper/toolbar_builder.rb | 27 +++++++++++++++++++++++
 1 file changed, 27 insertions(+)
Comment 12 CFME Bot 2016-04-22 09:51:19 EDT
New commit detected on cfme/5.5.z:
https://code.engineering.redhat.com/gerrit/gitweb?p=cfme.git;a=commitdiff;h=637ab77aadae93ba54cbe4e47ee5c6edddbccfb3

commit 637ab77aadae93ba54cbe4e47ee5c6edddbccfb3
Author:     Jozef Zigmund <jzigmund@redhat.com>
AuthorDate: Tue Mar 15 17:00:53 2016 +0100
Commit:     Jozef Zigmund <jzigmund@redhat.com>
CommitDate: Mon Apr 18 16:04:56 2016 +0200

    Hide toolbar Add/Edit actions in CatalogItem#show when user has view permission only
    
    https://bugzilla.redhat.com/show_bug.cgi?id=1213840

 app/helpers/application_helper/toolbar_builder.rb | 27 +++++++++++++++++++++++
 1 file changed, 27 insertions(+)
Comment 13 Aziza Karol 2016-05-04 03:40:56 EDT
User unable to modify catalog items when it has only access to view permission.

Verified:5.6.0.5-beta2.4.20160503153816_1fb554f
Comment 15 errata-xmlrpc 2016-06-29 10:54:02 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2016:1348

Note You need to log in before you can comment on or make changes to this bug.