Bug 1477015 - [RFE] A non-admin users with view permissions are unable to view templates details since they are only displayed in the edit form.
Summary: [RFE] A non-admin users with view permissions are unable to view templates de...
Keywords:
Status: NEW
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Provisioning Templates
Version: 6.2.10
Hardware: Unspecified
OS: Unspecified
medium
low
Target Milestone: Unspecified
Assignee: satellite6-bugs
QA Contact: Roman Plevka
URL:
Whiteboard:
: 1487989 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-08-01 05:02 UTC by Jayant Bhatia
Modified: 2020-12-15 01:25 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Foreman Issue Tracker 20973 Normal New A non-admin users with view permissions are unable to view resource details since they are only displayed in the edit fo... 2021-01-08 14:05:43 UTC
Red Hat Knowledge Base (Solution) 3300651 None None None 2018-06-29 13:31:12 UTC

Description Jayant Bhatia 2017-08-01 05:02:23 UTC
Description of problem:

A non-admin user with viewer role or 'view_provisioning_templates' permission is only able to see the list (name) of provisioning templates and unable to see the template box or details of the provisioning template.

Version-Release number of selected component (if applicable):


How reproducible: (Always)

Steps to Reproduce:

1) Create a non-admin user and assign 'Viewer' role to it or assign a custom role having 'view_provisioning_templates' permissions filter added to it.

2) From Satellite web interface navigate to 'Hosts' -> 'Provisioning templates'.

3) Click on the name of any provisioning templates being listed.

Actual results:

No action takes place and provisioning template details are not opened.

Expected results:

The template box or details of provisioning template should be visible with read only permission.

Additional info:

The issue is reproducible on Satellite version 6.2.10

Comment 1 Marek Hulan 2017-08-01 08:46:36 UTC
to see a template box (edit form) user must have edit_provisioning_templates permission, could you verify that adding this permissions helps? I think it's consistent with all other pages, view permission only allows user to display the resources in index page.

Comment 2 Andrew Schofield 2017-08-01 11:59:47 UTC
(In reply to Marek Hulan from comment #1)
> to see a template box (edit form) user must have edit_provisioning_templates
> permission, could you verify that adding this permissions helps? I think
> it's consistent with all other pages, view permission only allows user to
> display the resources in index page.

I can confirm that. 

However, if I have view_provisioning_templates I *should* be able to view the templates. I can do this via hammer (and the API). The web UI should reflect these permissions.

Comment 4 Marek Hulan 2017-08-04 13:42:59 UTC
I agree but that would mean displaying a different, read-only, form. As I said, it works this way for every resource, good example is subnet. If we change it, we should change it everywhere. A simple solution might be just disabling the submit button. I'll change the BZ title to match it. As you can imagine this would be a big change so it can take a while.

Comment 5 Tomer Brisker 2017-09-17 15:59:51 UTC
Created redmine issue http://projects.theforeman.org/issues/20973 from this bug

Comment 7 Marek Hulan 2017-11-20 21:17:09 UTC
*** Bug 1487989 has been marked as a duplicate of this bug. ***

Comment 9 Bryan Kearney 2019-02-07 12:09:28 UTC
The Satellite Team is attempting to provide an accurate backlog of bugzilla requests which we feel will be resolved in the next few releases. We do not believe this bugzilla will meet that criteria, and have plans to close it out in 1 month. This is not a reflection on the validity of the request, but a reflection of the many priorities for the product. If you have any concerns about this, feel free to contact Red Hat Technical Support or your account team. If we do not hear from you, we will close this bug out. Thank you.

Comment 12 Mike McCune 2020-12-09 22:17:34 UTC
Upon review of our valid but aging backlog the Satellite Team has concluded that this Bugzilla does not meet the criteria for a resolution in the near term, and are planning to close in approximately a month. If you have any concerns about this, please contact your Red Hat Account team.  Thank you.


Note You need to log in before you can comment on or make changes to this bug.