Bug 2086303 - non-priv user can't create VM when namespace is not selected
Summary: non-priv user can't create VM when namespace is not selected
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Container Native Virtualization (CNV)
Classification: Red Hat
Component: User Experience
Version: 4.11.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: 4.11.0
Assignee: Aviv Turgeman
QA Contact: Guohua Ouyang
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-05-15 13:17 UTC by Aviv Turgeman
Modified: 2023-11-13 08:15 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-09-14 19:33:33 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
create VM error screenshot (123.74 KB, image/png)
2022-05-15 13:17 UTC, Aviv Turgeman
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github kubevirt-ui kubevirt-plugin pull 417 0 None Merged Bug 2086303: non-priv user can't create VM when namespace is not selected 2022-05-31 23:44:10 UTC
Red Hat Issue Tracker CNV-18249 0 None None None 2023-11-13 08:15:04 UTC
Red Hat Product Errata RHSA-2022:6526 0 None None None 2022-09-14 19:33:45 UTC

Description Aviv Turgeman 2022-05-15 13:17:11 UTC
Created attachment 1879844 [details]
create VM error screenshot

Description of problem:
a non-priv user can not create a VM if 'all-namespaces' is selected as namespace.

Version-Release number of selected component (if applicable):


How reproducible:
100%

Steps to Reproduce:
1. login as non-priv user and navigate to Virtualization -> Catalog
2. select any template (make sure no namespace is selected)
3. click on "Customize VirtualMachine"
4. click on "Review and create Virtual Machine"
5. get following error:
Create VirtualMachine error
processedtemplates.template.openshift.io is forbidden: User "test" cannot create resource "processedtemplates" in API group "template.openshift.io" in the namespace "default"

Actual results:
since no namespace was selected, we assign the namespace "default" to our process request, as non-priv user has no permission to process a template in that namespace we fail

Expected results:
we want to alert the user that there is no namespace selected, and should not allowed to continue with the create VM process

Additional info:

Comment 1 Leon Kladnitsky 2022-05-31 23:48:35 UTC
Verified on CNV-v4.11.0-423/OCP-v4.11.0-36. 
When logged as non-pruv user, there's no "all-namespaces" option, therefore the user has to select or create project

Comment 4 errata-xmlrpc 2022-09-14 19:33:33 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Important: OpenShift Virtualization 4.11.0 Images security and bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2022:6526


Note You need to log in before you can comment on or make changes to this bug.