Bug 1572176 - [registration]Read-only admin user can access update method both in admin domain and IP address controller
Summary: [registration]Read-only admin user can access update method both in admin do...
Alias: None
Product: OpenShift Online
Classification: Red Hat
Component: Accounts and Billing
Version: 3.x
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: ---
Assignee: Timothy Williams
QA Contact: yufchang
Depends On:
TreeView+ depends on / blocked
Reported: 2018-04-26 10:39 UTC by yufchang
Modified: 2018-05-29 14:12 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-05-29 14:12:49 UTC
Target Upstream Version:

Attachments (Terms of Use)
domain (177.47 KB, image/png)
2018-04-26 10:39 UTC, yufchang
no flags Details

Description yufchang 2018-04-26 10:39:18 UTC
Created attachment 1427128 [details]

Description of problem:
Read-only admin user can approve subscription

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.Prepare a read-only admin user to login registration, enter admin panel->domain
2.try to edit/whitelist/.. domain record
3. enter admin panel->ip address
4.try to edit/whitelist....ip address record

Actual results:
Update related buttons can be accessed

Expected results:
Any of Update related Buttons should be unavailable

Comment 1 Timothy Williams 2018-04-27 19:51:44 UTC
Fixed in STG

Comment 4 yufchang 2018-05-02 06:05:31 UTC
When click action button(eg: whitelist,blacklist) in IP address admin controller, met :We're sorry, but something went wrong...
checked in code.Verified.

Note You need to log in before you can comment on or make changes to this bug.