Bug 1848492 - Button to log out from Grafana and Prometheus web UI
Summary: Button to log out from Grafana and Prometheus web UI
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Monitoring
Version: 3.11.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: 3.11.z
Assignee: Pawel Krupa
QA Contact: Junqi Zhao
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-06-18 13:05 UTC by Daniele
Modified: 2023-10-06 20:42 UTC (History)
10 users (show)

Fixed In Version: rh-container@k8s.jp.nec.com
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-07-27 13:49:10 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift cluster-monitoring-operator pull 837 0 None closed Bug 1848492: Enforce 24h cookie expiration time 2021-01-21 09:09:39 UTC
Red Hat Product Errata RHBA-2020:2990 0 None None None 2020-07-27 13:49:22 UTC

Description Daniele 2020-06-18 13:05:28 UTC
Description of problem:
There's is no "log out" button on the Graphana web ui.
On support cases it's been mentioned that the oauth token gets expired after 24 hours, so the user might have to login again to the web UI of Grafana and Prometheus.
This still doesn't give customers a way to forcefully close the session and feels like a possible security issue.

Version-Release number of selected component (if applicable):
OCP 3.11

How reproducible:
always

Steps to Reproduce:
Login into graphana. 
Close tab. 
Reopen.


Actual results:
Still logged in

Expected results:
Users can click a button to end their session

Additional info:
From the customer's point of view, this is a bug.
I understand it can be a RFE, but then the security implications of this should be addressed somewhere (maybe docs?).

Comment 10 Junqi Zhao 2020-07-20 10:16:54 UTC
tested with cluster-monitoring-operator:v3.11.248, cookie expiration time for alertmanager/prometheus/grafana is 24h

Comment 12 errata-xmlrpc 2020-07-27 13:49:10 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:2990

Comment 13 Masaki Hatada 2020-08-04 08:41:09 UTC
Dear Red Hat,

Our customer asked the same request as this bugzilla for OCP4.
The request of Comment #0 is to add logout button to prometheus and grafana, but https://github.com/openshift/cluster-monitoring-operator/pull/837 seems not to implement the feature requested by Comment #0.

That's very weird for us.
How did Red Hat handle Comment #0's request?
Does Red Hat have a plan to implement logout button for prometheus and grafana?

Please let us know the above information if possible.
(I have no permission to read private comment)

Best Regards,
Masaki Hatada

Comment 14 Ferdous 2020-11-20 15:09:46 UTC
Hello,

Seems like it's not resolved on Openshift 3.11/Grafana. Any progress on this issue?

Thanks,
Ferdous

Comment 15 Red Hat Bugzilla 2023-09-14 06:02:22 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days


Note You need to log in before you can comment on or make changes to this bug.