Bug 536414 (RHQ-766) - Non-privileged users should not even see the admin functions they don't have access to
Summary: Non-privileged users should not even see the admin functions they don't have ...
Keywords:
Status: CLOSED NEXTRELEASE
Alias: RHQ-766
Product: RHQ Project
Classification: Other
Component: No Component
Version: 1.1pre
Hardware: All
OS: All
medium
medium
Target Milestone: ---
: ---
Assignee: RHQ Project Maintainer
QA Contact:
URL: http://jira.rhq-project.org/browse/RH...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-08-28 18:18 UTC by Jeff Weiss
Modified: 2014-11-09 22:50 UTC (History)
1 user (show)

Fixed In Version: 1.2
Clone Of:
Environment:
Last Closed:
Embargoed:
jweiss: archived+


Attachments (Terms of Use)

Description Jeff Weiss 2008-08-28 18:18:00 UTC
i'm noticing that a view-only user still sees the same admin page as rhqadmin.  in fact, it lets you get as far as typing in all the info for creating a new user before it tells you that you aren't allowed to do it.  this is not how I would expect it to work.  There's probably a lot of bugs i could open on this that would be fixed just by getting rid of the admin page for non-admin users
For instance, creating a role gives a wrong error message "Failed to save the role - make sure one does not already exist with that name".   The real reason is the user doesn't have permission to create roles.  

Comment 1 Heiko W. Rupp 2008-09-08 15:24:31 UTC
From IT#218424

"
However, even if the logged in LDAP user has no roles associated with it, the user is able to access the Administration section from within the JBoss ON GUI.

I think this is a severe security limitation.

The logged in LDAP user can view users, list the current roles, can see the server configuration etc. Although it is not able to modify any settings, I think the user should not be able to see such key information and Administration settings.
"

Comment 2 Joseph Marques 2009-04-28 09:02:42 UTC
when mazz move all of the functions from the administration page up until the menu bar, he also made sure to handle display of the menu items based on the user's permissions.

Comment 3 Red Hat Bugzilla 2009-11-10 21:16:29 UTC
This bug was previously known as http://jira.rhq-project.org/browse/RHQ-766



Note You need to log in before you can comment on or make changes to this bug.