Bug 535022 (RHQ-1761) - User without "Configure" permission can still change group config (if he is a member of that group role)
Summary: User without "Configure" permission can still change group config (if he is a...
Keywords:
Status: CLOSED NOTABUG
Alias: RHQ-1761
Product: RHQ Project
Classification: Other
Component: No Component
Version: 1.2
Hardware: All
OS: All
medium
medium
Target Milestone: ---
: ---
Assignee: Ian Springer
QA Contact: Jeff Weiss
URL: http://jira.rhq-project.org/browse/RH...
Whiteboard:
Depends On:
Blocks: RHQ-1386
TreeView+ depends on / blocked
 
Reported: 2009-03-10 19:48 UTC by Jeff Weiss
Modified: 2014-11-09 22:49 UTC (History)
2 users (show)

Fixed In Version: 1.2
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
rev3351
Last Closed:
Embargoed:
jweiss: archived+


Attachments (Terms of Use)

Description Jeff Weiss 2009-03-10 19:48:00 UTC
How to repeat:
As rhqadmin, create a compatible group (i used Datasources).  Create a role with all perms except "Configure".  Add a user to the role and the compat group to the role.

Log out and log in as that user.  Go to the compat group config page, Edit,  change one of the values, click save.  The update succeeds.  It should fail because the user doesn't have configure permission.

Comment 1 Ian Springer 2009-03-12 04:09:23 UTC
Jeff, I wasn't able to reproduce this. You said you gave the test role all perms except CONFIGURE. Did this include the MANAGE_INVENTORY global perm? If so, that would also implicitly grant all resource perms, including CONFIGURE.

Note, r3400 adds better error messages for permission errors.


Comment 2 Jeff Weiss 2009-03-12 13:09:04 UTC
No MANAGE_INVENTORY wasn't checked, since that forces CONFIGURE on as well.  If you have a test server, let me see if I can repro it there.

Comment 3 Jeff Weiss 2009-03-12 16:22:23 UTC
oh, i see the problem now.  ips, i thought you were referring to "Manage security" role that enables the other roles

Comment 4 Red Hat Bugzilla 2009-11-10 20:46:06 UTC
This bug was previously known as http://jira.rhq-project.org/browse/RHQ-1761



Note You need to log in before you can comment on or make changes to this bug.