Bug 1468277 - Allow dedicated-admins to list/delete oauthclientauthorizations
Allow dedicated-admins to list/delete oauthclientauthorizations
Status: NEW
Product: OpenShift Container Platform
Classification: Red Hat
Component: RFE (Show other bugs)
3.4.1
Unspecified Unspecified
unspecified Severity medium
: ---
: ---
Assigned To: Abhishek Gupta
yasun
: OpsBlocker
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-07-06 10:26 EDT by bmorriso
Modified: 2017-10-16 11:06 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description bmorriso 2017-07-06 10:26:16 EDT
Description of problem:

Currently members of the dedicated-admin group are allowed to create and delete users but they can still be blocked from deleting users because the dedicated-admin group is not allowed to list/delete oauthclientauthorizations:

# // Running this command as dedicated-admin user john.doe@example.com
# oc delete user foo.bar@example.com
Error from server (Forbidden): User "john.doe@exmaple.com" cannot list all oauthclientauthorizations in the cluster


Allowing dedicated-admins to list/delete oauthclientauthorizations would resolve the above issue.

Version-Release number of selected component (if applicable):
3.4.1.18
Comment 1 Jackie 2017-10-15 18:16:18 EDT
Its been more than 3 months, is there a ETA for this bug fixing?

Note You need to log in before you can comment on or make changes to this bug.