Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1562777 - Approval permissions are not followed between different groups
Approval permissions are not followed between different groups
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance (Show other bugs)
5.8.0
All All
high Severity high
: GA
: 5.9.2
Assigned To: Libor Pichler
Landon LaSmith
: ZStream
Depends On: 1545395
Blocks:
  Show dependency treegraph
 
Reported: 2018-04-02 09:24 EDT by Satoe Imaishi
Modified: 2018-05-07 16:48 EDT (History)
6 users (show)

See Also:
Fixed In Version: 5.9.2.1
Doc Type: Release Note
Doc Text:
This release of Red Hat CloudForms corrects restrictions for Request visibility when the role is set to "Only User or Group Owned" or "Only User Owned".
Story Points: ---
Clone Of: 1545395
Environment:
Last Closed: 2018-05-07 16:47:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:1328 None None None 2018-05-07 16:48 EDT

  None (edit)
Comment 2 CFME Bot 2018-04-02 09:30:50 EDT
New commit detected on ManageIQ/manageiq/gaprindashvili:

https://github.com/ManageIQ/manageiq/commit/a1ec51830e537bb4d29099051675d7ab006d1d46
commit a1ec51830e537bb4d29099051675d7ab006d1d46
Author:     Gregg Tanzillo <gtanzill@redhat.com>
AuthorDate: Wed Mar 28 09:28:38 2018 -0400
Commit:     Gregg Tanzillo <gtanzill@redhat.com>
CommitDate: Wed Mar 28 09:28:38 2018 -0400

    Merge pull request #17208 from lpichler/restrict_miq_request_by_users_group

    Add ownership for MiqRequest in RBAC
    (cherry picked from commit 09697591a48eb2d1d994ec57d09a842844c0cab7)

    https://bugzilla.redhat.com/show_bug.cgi?id=1562777

 app/models/miq_request.rb | 20 +
 lib/rbac/filterer.rb | 19 +-
 spec/lib/rbac/filterer_spec.rb | 56 +
 3 files changed, 92 insertions(+), 3 deletions(-)
Comment 3 Landon LaSmith 2018-04-18 16:11:31 EDT
VERIFIED in 5.9.2.2. Request visibility was correctly restricted when the role was set to "Only User or Group Owned" OR "Only User Owned"
Comment 6 errata-xmlrpc 2018-05-07 16:47:51 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:1328

Note You need to log in before you can comment on or make changes to this bug.