Bug 203933 - Config Admins are allowed to see local config channels for systems they don't administer.
Config Admins are allowed to see local config channels for systems they don't...
Status: CLOSED CURRENTRELEASE
Product: Red Hat Network
Classification: Red Hat
Component: RHN/Web Site (Show other bugs)
rhn420
All Linux
medium Severity medium
: ---
: ---
Assigned To: Grant Gainey
Preethi Thomas
:
Depends On:
Blocks: rhn500h-config-mgmt
  Show dependency treegraph
 
Reported: 2006-08-24 12:21 EDT by Ken Ganong
Modified: 2007-04-18 13:48 EDT (History)
1 user (show)

See Also:
Fixed In Version: rhn500h
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-03-12 23:38:06 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ken Ganong 2006-08-24 12:21:24 EDT
In rhn_config_channel.get_user_chan_access, a config admin is given access to
any row in rhnConfigChannel that is part of his/her org.
Note: bug #201181 touches this same stored procedure.

Expected: Config Admins have access to all global config channels
(rhnConfigChannelType label = 'normal'), but only have access to local config
channels for which they have permissions to the associated server.
Comment 1 Grant Gainey 2006-11-15 10:43:44 EST
Now with whiteners, brighteners, *and* more ON_DEV-ness!
Comment 2 Grant Gainey 2006-12-04 17:05:28 EST
ON_QA, here we come!
Comment 3 Preethi Thomas 2007-01-10 14:32:32 EST
Cannot verify this, as the Local config channel list is missing.
Comment 4 Grant Gainey 2007-01-18 16:10:17 EST
See comments in BZ 147423 - local-channel-list has been removed.  This can be
tested by checking to see if cfg-admins can get access to -systems- that they
aren't supposed to be able to acess
Comment 5 Preethi Thomas 2007-01-19 08:56:55 EST
verified. rhn500h. qapush#5
Comment 6 Preethi Thomas 2007-03-07 12:32:21 EST
verified in stage.
Comment 7 Brandon Perkins 2007-03-12 23:38:06 EDT
Closed in the rhn500h Release.

Note You need to log in before you can comment on or make changes to this bug.