Bug 1907518 - Kamelets/Eventsource should be shown to user if they have create access
Summary: Kamelets/Eventsource should be shown to user if they have create access
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Dev Console
Version: 4.7
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: ---
: 4.7.0
Assignee: Jaivardhan Kumar
QA Contact: Gajanan More
Harsh Mishra
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-12-14 16:43 UTC by Jaivardhan Kumar
Modified: 2021-02-24 15:44 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: RBAC checks were not there for eventSources and KameletBinding so self provisioner with view only access can see sources in catalog but can't create one Consequence: self provisioner with view only access can see sources in catalog Fix: Added required RBAC check Result: User with required access can only see EventSource/Kamelets in catalog
Clone Of:
Environment:
Last Closed: 2021-02-24 15:43:42 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github openshift console pull 7543 0 None closed Bug 1907518: adds rbac for eventSource, KameletBinding and removes camelSource unwanted changes 2021-02-09 13:50:21 UTC
Red Hat Product Errata RHSA-2020:5633 0 None None None 2021-02-24 15:44:00 UTC

Description Jaivardhan Kumar 2020-12-14 16:43:47 UTC
Description of problem: Kamelets/EventSource should be shown to user if they have create access for EventSource / kameletBinding

Prerequisites (if any, like setup, operators/versions): Serverless Operator/Camel K Integration

Steps to Reproduce
1.Create CR of Integration Platform in a namespace as admin
2.Provide list/edit access to that namespace for another user
3.Non Admin can see kamelet source in catalog for eventSources
4.Can see above for eventSources as well

Actual results: 
Kamelets / EventSource shown to user but they can't create

Expected results: 
Kamelets / EventSource should be shown to user if they have create access for 
Source/kameletBinding

Reproducibility (Always/Intermittent/Only Once): Always

Build Details: 4.7.0-0.nightly-2020-12-10-120835

Additional info:

Comment 2 Vikram Raj 2021-01-07 17:02:57 UTC
Verified it and issue has been fixed.
Cluster build - 4.7.0-0.nightly-2020-12-21-131655

Comment 5 errata-xmlrpc 2021-02-24 15:43:42 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.7.0 security, bug fix, and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2020:5633


Note You need to log in before you can comment on or make changes to this bug.