Bug 2019646 - Permission error should pop-up immediately while clicking "Create VM" button on template page for view only user
Summary: Permission error should pop-up immediately while clicking "Create VM" button ...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Console Kubevirt Plugin
Version: 4.10
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 4.10.0
Assignee: Hilda Stastna
QA Contact: Guohua Ouyang
Depends On:
TreeView+ depends on / blocked
Reported: 2021-11-03 02:38 UTC by Guohua Ouyang
Modified: 2022-03-10 16:25 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2022-03-10 16:24:41 UTC
Target Upstream Version:

Attachments (Terms of Use)
create VM button on template page (508.35 KB, image/gif)
2021-11-03 02:38 UTC, Guohua Ouyang
no flags Details

System ID Private Priority Status Summary Last Updated
Github openshift console pull 10549 0 None open Bug 2019646: Display permission error modal for view only user 2021-11-25 08:43:36 UTC
Red Hat Product Errata RHSA-2022:0056 0 None None None 2022-03-10 16:25:01 UTC

Description Guohua Ouyang 2021-11-03 02:38:50 UTC
Created attachment 1839478 [details]
create VM button on template page

Description of problem:
Permission error should pop-up immediately while clicking "Create VM" button on template page for view only user, just like what it's done on "Add source" button.

Version-Release number of selected component (if applicable):
4.10 nightly

How reproducible:

Steps to Reproduce:
1. login with a view only user
$ oc adm policy add-role-to-user view test -n default
2. on template list page, select a template and click "Create VM" button 

Actual results:
view only user can continue after clicking "Create VM"

Expected results:
Permission error should pop-up immediately while clicking "Create VM" button

Additional info:

Comment 3 Guohua Ouyang 2021-12-06 07:45:53 UTC
This policy is also applied when a project admin user who has edit permission logged in.
1. create a nonprivilege user, ref: https://github.com/openshift/console/blob/master/test-prow-e2e.sh#L52
2. login and create a project
3. navigate to template list page
4. click "Create VM"

it pops up the error immediately too, however in this situation, the user has edit permission in their own project which should not popup such error.

Assign the bug back because of the regression problem found.

Comment 4 Guohua Ouyang 2021-12-15 03:18:58 UTC
Set the severity to high as it causes regression problem, project admin cannot use "Create VM" to create vm.

Comment 10 errata-xmlrpc 2022-03-10 16:24:41 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.10.3 security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.