Bug 1297738 - EVERYONE user is added twice when creating a new disks profile
Summary: EVERYONE user is added twice when creating a new disks profile
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: ovirt-engine
Classification: oVirt
Component: BLL.Storage
Version: 3.6.2.1
Hardware: Unspecified
OS: Unspecified
unspecified
low
Target Milestone: ---
: ---
Assignee: Martin Sivák
QA Contact: Petr Matyáš
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-01-12 10:54 UTC by Roman Mohr
Modified: 2022-06-27 08:03 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-07-04 10:21:15 UTC
oVirt Team: SLA
Embargoed:
sbonazzo: ovirt-4.2-
sbonazzo: ovirt-4.3-


Attachments (Terms of Use)
diks profile permission screenshot (133.38 KB, image/png)
2016-01-12 10:54 UTC, Roman Mohr
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHV-46618 0 None None None 2022-06-27 08:03:00 UTC

Description Roman Mohr 2016-01-12 10:54:22 UTC
Created attachment 1113906 [details]
diks profile permission screenshot

Description of problem:
EVERYONE user is assigned two times to a new disk profile


Version-Release number of selected component (if applicable):


How reproducible:
Create a disk profile and check it's permissions by clicking on it (see attached screenshot)


Steps to Reproduce:
1. Create an additional disk profile
2. Click on it in Storage->Disk Profiles->'profile name'
3. Look at the permissions

Actual results:
EVERYONE user is visible two times

Expected results:
EVERYONE user should only be there once

Additional info:

Comment 1 Roman Mohr 2016-01-13 15:09:57 UTC
So the default profile currently gets:

user admin and role Superuser
user EVERYONE with role DiskProfileEditor

Every new profile gets

user admin and role Superuser
user EVERYONE with role DiskProfileEditor
user EVERYONE with role DiskProfileUser

It might be more correct to have these permissions on the default policy:

user admin and role Superuser
user <CREATOR> with role DiskProfileEditor
user EVERYONE with role DiskProfileUser

New profiles should have:
user admin and role Superuser
user <CREATOR> with role DiskProfileEditor

to make it an explicit decision if new profiles should be available for everyone.

Comment 2 Doron Fediuck 2016-01-19 14:03:48 UTC
Roman note that not every user is a creator.
For example if I'm an end user (student), I may not be able to create a (disk, vNIC, VM), but I should still be able to consume one or more profiles based on
my permissions (including any LDAP group I belong to).

Comment 3 Michal Skrivanek 2018-07-04 10:22:38 UTC
doesn't seem interesting enough, no complaints anywhere, low severity

Please reopen if still interesting


Note You need to log in before you can comment on or make changes to this bug.