Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 745957 - [ipa webui] As a Host Administrator, user does not have access to the Host tab
[ipa webui] As a Host Administrator, user does not have access to the Host tab
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: ipa (Show other bugs)
6.1
Unspecified Unspecified
high Severity unspecified
: rc
: ---
Assigned To: Rob Crittenden
IDM QE LIST
:
Depends On:
Blocks: 748554
  Show dependency treegraph
 
Reported: 2011-10-13 10:11 EDT by Namita Soman
Modified: 2011-12-06 13:42 EST (History)
3 users (show)

See Also:
Fixed In Version: ipa-2.1.3-1.el6
Doc Type: Bug Fix
Doc Text:
Cause: Web UI does not take into account when non-admin user is a member of an administrative role and thus have more privileges than doing just self-service actions Consequence: User with administrative role (e.g. a Host Admin) is not allowed to access the related administrative Web UI section (e.g. a Hosts tab) Fix: Show the full administrative tabset for users with a role Result: Users with administrative role can access the respective sections and proceed with allowed actions
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-12-06 13:42:54 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1533 normal SHIPPED_LIVE Moderate: ipa security and bug fix update 2011-12-05 20:23:31 EST

  None (edit)
Description Namita Soman 2011-10-13 10:11:38 EDT
Description of problem:
A user is assigned the role of Host Admin, and kinits, goes to UI. This user cannot perform any Hosts related actions.
Same is true with any other role as well.

Version-Release number of selected component (if applicable):
ipa-server-2.1.2-2.el6.x86_64

How reproducible:
always

Steps to Reproduce:
1. Add a user
2. Add a new Role - Host Admins, enroll the user added above
3. Edit this role, to enroll "Host Administrators" as a privilege
4. kinit as the user
5. Go to the UI
  
Actual results:
There is no Host tab

Expected results:
Host tab is available for this user to allow adding/editing hosts

Additional info:
Comment 2 Dmitri Pal 2011-10-13 12:09:27 EDT
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/1970
Comment 3 Rob Crittenden 2011-10-13 18:24:13 EDT
fixed upstream

master: 93ddfd008af6cd720c6f8c6902e8d24b06d59e72

ipa-2-1: edd334c67acf1f797103276c6e6a8978d9ff72e9
Comment 5 Yi Zhang 2011-10-28 12:16:36 EDT
verified on rhel6.2 i386

[yi@i386a(101) ~] rpm -qi ipa-server
Name        : ipa-server                   Relocations: (not relocatable)
Version     : 2.1.3                             Vendor: Red Hat, Inc.
Release     : 2.el6                         Build Date: Tue 18 Oct 2011 11:12:34 AM PDT
Install Date: Thu 20 Oct 2011 10:39:05 AM PDT      Build Host: x86-002.build.bos.redhat.com
Group       : System Environment/Base       Source RPM: ipa-2.1.3-2.el6.src.rpm
Size        : 3355311                          License: GPLv3+
Signature   : (none)
Packager    : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla>
URL         : http://www.freeipa.org/
Summary     : The IPA authentication server
Description :
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). If you are installing an IPA server you need
to install this package (in other words, most people should NOT install
this package).
Comment 6 Martin Kosek 2011-10-31 15:06:32 EDT
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Cause: Web UI does not take into account when non-admin user is a member of an administrative role and thus have more privileges than doing just self-service actions
Consequence: User with administrative role (e.g. a Host Admin) is not allowed to access the related administrative Web UI section (e.g. a Hosts tab)
Fix: Show the full administrative tabset for users with a role
Result: Users with administrative role can access the respective sections and proceed with allowed actions
Comment 7 errata-xmlrpc 2011-12-06 13:42:54 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2011-1533.html

Note You need to log in before you can comment on or make changes to this bug.