Bug 2214285 - User with only view-host permission can attempt to schedule a job which leads to Categories list failed with: Request failed with status code 403
Summary: User with only view-host permission can attempt to schedule a job which leads...
Keywords:
Status: NEW
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Remote Execution
Version: 6.14.0
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: Unspecified
Assignee: satellite6-bugs
QA Contact: Satellite QE Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-06-12 13:28 UTC by addubey
Modified: 2023-08-16 10:24 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SAT-18436 0 None None None 2023-06-15 14:28:58 UTC

Description addubey 2023-06-12 13:28:43 UTC
Created attachment 1970428 [details]
page_view

Description of problem: User with only view-host permission can attempt to schedule a job which leads to errors -> Categories list failed with Request failed with status code 403


Version-Release number of selected component (if applicable): 6.14.0 snap -3 


How reproducible: Always 


Steps to Reproduce:
1. Create a user with a view-host permission 
2. Navigate to Hosts -> All hosts -> select host 
3. Try to click on the schedule job button, it opens up a broken page for initiating the rex job.

Actual results: Page opens up stating Job category - Error and States -> Categories list failed with: Request failed with status code 403


Expected results: I believe users with such permission should not be able to run/click on the schedule job button like the dropdown of all jobs is locked for example.


Additional info:

Comment 1 Brad Buckingham 2023-06-15 14:28:24 UTC
Is this a regression from earlier Satellite release?

Is there a stack trace that can be attached?


Note You need to log in before you can comment on or make changes to this bug.