Bug 493744 - Normal user can see "permission error" on configuration tab
Summary: Normal user can see "permission error" on configuration tab
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Server
Version: 530
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Jay Dobies
QA Contact: Sayli Karmarkar
URL:
Whiteboard:
: 493713 (view as bug list)
Depends On:
Blocks: 456985
TreeView+ depends on / blocked
 
Reported: 2009-04-02 21:59 UTC by Sayli Karmarkar
Modified: 2015-03-23 01:09 UTC (History)
4 users (show)

Fixed In Version: sat530
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-09-10 20:35:13 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Sayli Karmarkar 2009-04-02 21:59:03 UTC
Steps to Reproduce:
1. Create a user. Don't give any special permission or role. Just the default user creation.  
2. Login as user
3. Click on configuration tab
  
Actual results:
Permission Error.

You do not have the appropriate permission set to access the requested page. You may have reached this error page in one of several ways:

   1. You are using Konqueror 3.0, which does not handle form variables properly in all cases. Continuing to use Konqueror 3.0 will have unexpected results. If you are using Konqueror 3.0, please use another browser. 
...
...


Expected results:
No such error.

Comment 1 Jay Dobies 2009-04-07 20:13:14 UTC
*** Bug 493713 has been marked as a duplicate of this bug. ***

Comment 2 Jay Dobies 2009-04-07 20:15:08 UTC
Commit: 4bd4d644447d280265c3bf70c78b97583a77fb31

java/code/webapp/WEB-INF/nav/sitenav-authenticated.xml

Added configuration admin ACL to configuration tab

Comment 3 Jay Dobies 2009-04-07 20:19:00 UTC
Vader Commit: de6f0671dfcaff91e22ffc8d5e93ec67a756364f

Comment 4 Sayli Karmarkar 2009-04-28 21:01:19 UTC
Verified. Cannot see configuration tab with default permissions, After adding configuration admin role, con figuration tab is seen and is accessible.

Comment 5 John Sefler 2009-08-26 21:47:29 UTC
Verified on staged (Satellite-5.3.0-RHEL5-re20090724.0) with updates from Aug 20, 2009

Verified that a newly created "normal user" (without "Configuration Administrator") cannot see the "Configuration" tab and that if the https://<sat>/rhn/configuration/Overview.do url is loaded, then the "Permission Error" message is displayed.  When the "Configuration Administrator" role is assigned to the user, then access to the "Configuration" tab is a success.

moving to RELEASE_PENDING

Comment 6 Brandon Perkins 2009-09-10 20:35:13 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHEA-2009-1434.html


Note You need to log in before you can comment on or make changes to this bug.