Bug 1628520 - User unable to retire his owned service from Self service portal
Summary: User unable to retire his owned service from Self service portal
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: API
Version: 5.9.6
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: GA
: 5.10.z
Assignee: Gregg Tanzillo
QA Contact: Niyaz Akhtar Ansari
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-09-13 10:27 UTC by Niladri Roy
Modified: 2021-12-10 17:28 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-04-30 19:12:37 UTC
Category: ---
Cloudforms Team: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
Services Permissions for role Copied-EvmRole-user_self_service (41.84 KB, image/png)
2018-09-13 17:24 UTC, Chris Hale
no flags Details
SUI permissions for retire (43.37 KB, image/png)
2018-09-13 17:24 UTC, Chris Hale
no flags Details

Description Niladri Roy 2018-09-13 10:27:00 UTC
Description of problem:
User gets below error in api.log when trying to retire service from SUI

[----] E, [2018-09-10T17:30:04.562690 #7392:ad794c] ERROR -- : MIQ(Api::ServicesController.api_error) API Error
[----] E, [2018-09-10T17:30:04.562777 #7392:ad794c] ERROR -- : MIQ(Api::ServicesController.api_error) Api::ForbiddenError: Use of Action retire is forbidden

Version-Release number of selected component (if applicable):
5.9.4.7

How reproducible:
Always

Steps to Reproduce:
1. Create a catalog item as UserA, make sure UserA is the owner
2. Login to Service UI as UserA
3. Try to retire the service by following below

https://access.redhat.com/documentation/en-us/red_hat_cloudforms/4.6/html-single/self_service_user_interface_guide/#retiring-service

Actual results:
Error in the UI with text "There was an error retiring this service"

Expected results:
The service gets retired

Additional info:

Comment 8 Chris Hale 2018-09-13 17:24:05 UTC
Created attachment 1483109 [details]
Services Permissions for role Copied-EvmRole-user_self_service

Comment 9 Chris Hale 2018-09-13 17:24:53 UTC
Created attachment 1483110 [details]
SUI permissions for retire

Comment 11 drew uhlmann 2019-04-17 12:43:26 UTC
May I've a reproducer that's alive, please?

Comment 12 drew uhlmann 2019-04-17 16:35:04 UTC
Or a log link that doesn't 404?

Comment 13 Niladri Roy 2019-04-18 05:53:39 UTC
Hi Drew,

I have re-downloaded the logs at http://collab-shell.usersys.redhat.com/02179065/

ERROR:
[----] E, [2018-09-10T17:06:57.319693 #7392:ad6fb0] ERROR -- : MIQ(Api::TasksController.api_error) Api::ForbiddenError: Use of the read action is forbidden

I think this error is due to this permission, when this below role permission was ON, the error didn't appear
  Everything > Services > Requests > Operate > Approve and Deny

I was working on a separate case where I noticed this behaviour in 5.10.0.33 as well.
Please see BZ 1701098

Comment 14 drew uhlmann 2019-04-18 19:39:48 UTC
Hey Tina, per the last line of comment 13, https://bugzilla.redhat.com/show_bug.cgi?id=1701098 is similar. Could I please get your opinion on how this is supposed to work?


Note You need to log in before you can comment on or make changes to this bug.