Bug 1375722 - CloudForms 4.1 Child tenants are allowed to view other child tenants Service Requests
Summary: CloudForms 4.1 Child tenants are allowed to view other child tenants Service ...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance
Version: 5.6.0
Hardware: All
OS: All
medium
medium
Target Milestone: GA
: 5.9.0
Assignee: Libor Pichler
QA Contact: Pavol Kotvan
URL:
Whiteboard: tenant
Depends On:
Blocks: 1461513
TreeView+ depends on / blocked
 
Reported: 2016-09-13 20:31 UTC by myoder
Modified: 2020-12-14 07:44 UTC (History)
8 users (show)

Fixed In Version: 5.9.0.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1461513 (view as bug list)
Environment:
Last Closed: 2018-03-06 15:52:46 UTC
Category: ---
Cloudforms Team: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
Screenshot of Tenant viewing Service Request of another tenant (111.43 KB, image/png)
2016-09-13 20:31 UTC, myoder
no flags Details

Description myoder 2016-09-13 20:31:08 UTC
Created attachment 1200613 [details]
Screenshot of Tenant viewing Service Request of another tenant

4.1 Description of problem: A child tenant is allowed to see other child tenants Service Requests


Version-Release number of selected component (if applicable): CloudForms 4.1


How reproducible: Always


Steps to Reproduce:
1. Have a child tenant named Customer C make a Service Request
2. Login as an admin child tenant named Customer A.
3. Go to Services -> Requests and view the Service Requests made by child tenant Customer C.

Actual results: Customer A child tenant is allowed to see the names of other child tenants that have made a Service Request.


Expected results: Customer A child tenant should not see the names of other child tenants that have made a Service Request


Additional info:

Comment 5 Harpreet Kataria 2016-10-24 17:13:39 UTC
Gregg,

I am wondering if MiqRequest should be included in list here https://github.com/ManageIQ/manageiq/blob/master/lib/rbac/filterer.rb#L8

Let me know.

Thanks,
~Harpreet


Note You need to log in before you can comment on or make changes to this bug.