Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
Red Hat Satellite engineering is moving the tracking of its product development work on Satellite to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "Satellite project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs will be migrated starting at the end of May. If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "Satellite project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/SAT-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Description of problem:
Non-admin user with 'Viewer' role can see tasks and select All tasks. Individual task checkbox is greyed out but Select All is available. Non Admin user can check all task and perform Action, Cancel Selected, Resume Selected, Force Cancel selected
Version-Release number of selected component (if applicable):
6.9
How reproducible:
Always
Steps to Reproduce:
1. Create a non-admin user with 'viewer' role.
2. Login with above non admin role.
3. GoTo Monitor -> Tasks -> Select All tasks -> Select Action -> Resume selected
Actual results:
It allow to select all tasks
Expected results:
It should not allow to select all
Additional info:
The current stance is:
1) The user can select all tasks, even if they cannot select every single task separately
2) The user can try to perform a bulk action against the selection
3) The bulk action is performed only against the tasks against which the user is permitted to perform the action
We cannot forbid users from trying to select all, because we cannot be sure that there is nothing the user could select on other pages. For the same reason, we cannot forbid them from trying to perform a bulk action on all selected tasks, because there may be a task in the selection against which they are allowed to perform the action.
> Non Admin user can check all task and perform Action, Cancel Selected, Resume Selected, Force Cancel selected
They can try to do that. Will the tasks be actually cancelled/resumed/force cancelled?
(In reply to Adam Ruzicka from comment #1)
> The current stance is:
> 1) The user can select all tasks, even if they cannot select every single
> task separately
> 2) The user can try to perform a bulk action against the selection
> 3) The bulk action is performed only against the tasks against which the
> user is permitted to perform the action
>
> We cannot forbid users from trying to select all, because we cannot be sure
> that there is nothing the user could select on other pages. For the same
> reason, we cannot forbid them from trying to perform a bulk action on all
> selected tasks, because there may be a task in the selection against which
> they are allowed to perform the action.
Here, I am talking of the viewer role specifically, which will have granular permission like "view_tasks". With this permission, I do not think, the user will have any tasks with permissions to perform the actions(Cancel, Resume, force ).
>
> > Non Admin user can check all task and perform Action, Cancel Selected, Resume Selected, Force Cancel selected
>
> They can try to do that. Will the tasks be actually cancelled/resumed/force
> cancelled?
With view-only permission, I do not expect this to be visible.
Checked on snap_6.10.0_2.0, viewer is not able to operate on tasks, but the UI sends mixed signals, the select-all checkbox and the confirmation infobox are actin as if selection was possible even though the individual checkboxes are grayed-out (see screenshots).
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (Moderate: Satellite 6.10 Release), and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2021:4702