Bug 2276590 - [Ceph Dashboard] dashboard landing page displays Access Denied when logged in with read-only user
Summary: [Ceph Dashboard] dashboard landing page displays Access Denied when logged in...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat Storage
Component: Ceph-Dashboard
Version: 7.1
Hardware: x86_64
OS: Linux
unspecified
high
Target Milestone: ---
: 7.1z1
Assignee: Pedro González Gómez
QA Contact: Vinayak Papnoi
Akash Raj
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-04-23 08:45 UTC by Vinayak Papnoi
Modified: 2024-08-07 11:21 UTC (History)
6 users (show)

Fixed In Version: ceph-18.2.1-218.el9cp
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2024-08-07 11:21:54 UTC
Embargoed:
akraj: needinfo? (pegonzal)
akraj: needinfo-


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github ceph ceph pull 57070 0 None open mgr/dashboard: fix readonly landingpage 2024-05-22 10:42:07 UTC
Red Hat Issue Tracker RHCEPH-8868 0 None None None 2024-04-23 09:48:25 UTC
Red Hat Issue Tracker RHCSDASH-1367 0 None None None 2024-04-23 09:48:31 UTC
Red Hat Product Errata RHBA-2024:5080 0 None None None 2024-08-07 11:21:57 UTC

Description Vinayak Papnoi 2024-04-23 08:45:39 UTC
Created attachment 2028471 [details]
dashboard landing page displaying access denied when logged in with read-only user

Description of problem:

When a read-only user is used to login to the dashboard UI , the landing page (and multiple other pages) display Access Denied along with a message "Sorry, you don't have permission to view this page or resource."


Version-Release number of selected component (if applicable):

Ceph 7.1
18.2.1-149.el9cp


How reproducible:
1/1


Steps to Reproduce:

1. Deploy a ceph cluster with monitoring stack and dashboard enabled
2. Login to the dashboard using admin and create a read-only user
3. Logout and log back in using the read-only user created


Actual results:

dashboard landing page displays "Access Denied"


Expected results:

All pages should be visible to a read-only user. The admin operations only should be inaccessible.


Additional info:

Comment 9 errata-xmlrpc 2024-08-07 11:21:54 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Red Hat Ceph Storage 7.1 security and bug fix update.), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2024:5080


Note You need to log in before you can comment on or make changes to this bug.