Bug 1313904 - When an AD group is assigned superuser access to a cluster, users in that group are not given access to the VMs in that cluster
Summary: When an AD group is assigned superuser access to a cluster, users in that gro...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: ovirt-engine
Version: 3.5.7
Hardware: All
OS: Linux
high
high
Target Milestone: ovirt-4.0.4
: ---
Assignee: Arik
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1320343
TreeView+ depends on / blocked
 
Reported: 2016-03-02 15:15 UTC by Allie DeVolder
Modified: 2019-11-14 07:33 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-08-15 06:52:25 UTC
oVirt Team: Virt
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Allie DeVolder 2016-03-02 15:15:51 UTC
Description of problem:
When an AD group is assigned superuser access to a cluster, users in that group are not given access to the VMs in that cluster

Version-Release number of selected component (if applicable):
rhevm-3.5.7-0.1

How reproducible:
very

Steps to Reproduce:
1. Assign a group 'superuser' role on a cluster
2. log in as member of that group
3. attempt to access VM in that cluster

Actual results:
User not given access to that VM

Expected results:
User should have access to the VM as per the cluster settings

Comment 1 Oved Ourfali 2016-03-03 06:24:05 UTC
Can you elaborate what do you mean by access to VM?

Comment 3 Tomas Jelinek 2016-03-07 09:33:46 UTC
@Arik, any thoughts?

Comment 4 Arik 2016-04-10 13:42:04 UTC
(In reply to Tomas Jelinek from comment #3)
> @Arik, any thoughts?

It seems that by design admin roles are not inherited from clusters to VMs.
Therefore it is definitely not something for a z-stream.

Allan, could you please elaborate on the implication on the user? is something missing in the UI? are there specific operations the user cannot do because of this?

Comment 5 Tomas Jelinek 2016-04-14 12:33:26 UTC
since it is by design pushing out of 3.6.6.
Setting to 4.0 in case we will get to some enhancement we want to implement.

Comment 6 Yaniv Lavi 2016-05-09 11:00:50 UTC
oVirt 4.0 Alpha has been released, moving to oVirt 4.0 Beta target.

Comment 15 Michal Skrivanek 2016-07-21 12:10:47 UTC
this works as per design. We need to review the design

Comment 16 Michal Skrivanek 2016-07-28 07:53:47 UTC
is there any input/feedback from infra about how roles work?

Comment 22 Tomas Jelinek 2016-08-15 06:52:25 UTC
As explained by infra in comment 21: There is a difference if you use the user level api or admin level (e.g. the UI user portal vs webadmin; in REST Filter: true vs false header).
If you use the user level API, you need to assign user roles (in this case UserVmManager, not superuser).

This is by design, closing as not a bug.
If this is a big issue or someone has a good use case to change it, please reopen as RFE.


Note You need to log in before you can comment on or make changes to this bug.