Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1441637 - Tag Visibility | All cloud key pairs is visible for restricted user
Tag Visibility | All cloud key pairs is visible for restricted user
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance (Show other bugs)
5.7.0
Unspecified Unspecified
high Severity medium
: GA
: 5.9.0
Assigned To: Gregg Tanzillo
Ruslana Babyuk
tag:cloud:rbac
:
: 1403008 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-12 07:41 EDT by Ruslana Babyuk
Modified: 2018-03-01 08:11 EST (History)
9 users (show)

See Also:
Fixed In Version: 5.9.0.1
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-03-01 08:11:36 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: Bug
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0380 normal SHIPPED_LIVE Moderate: Red Hat CloudForms security, bug fix, and enhancement update 2018-03-01 13:37:12 EST

  None (edit)
Description Ruslana Babyuk 2017-04-12 07:41:59 EDT
Description of problem:
Restricted user can see all key pairs, while the tag is set in the group

Version-Release number of selected component (if applicable):5.7.2.1

How reproducible:
100%

Steps to Reproduce:
1. Add cloud provider(in my case rhos7-ga)
2. Add role, group, and user
3. Assign tag in the group
4. Add tag to any key pair
5. Login as restricted user
6. Navigate to Key Pairs page

Actual results:
All list of key pairs is visible

Expected results:
Only tagged key pair should be visible for the user
Comment 2 Ruslana Babyuk 2017-04-12 07:47:21 EDT
The same issue also reproduces with Host Aggregates
Comment 3 Libor Pichler 2017-06-13 08:07:40 EDT
*** Bug 1403008 has been marked as a duplicate of this bug. ***
Comment 7 errata-xmlrpc 2018-03-01 08:11:36 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:0380

Note You need to log in before you can comment on or make changes to this bug.